Breach 058 / 076

MGM Grand Data Breach - September 2023

In September 2023, MGM Resorts International experienced a major cyberattack orchestrated by the Scattered Spider group, leading to significant operational disruptions and an estimated $80 million in financial losses. The attackers exploited social engineering methods, particularly vishing, to breach MGM’s systems and compromise personal data including names, driver’s license numbers, and Social Security numbers. This attack underscores vulnerabilities in service desk operations and highlights the use of sophisticated ransomware tactics.
Sector
Hospitality & Food Service
Year

Executive Summary

In September 2023, MGM Resorts International experienced a major cyberattack attributed to the hacking group Scattered Spider, known for its association with the ALPHV/BlackCat ransomware group. The attack resulted in significant disruptions to operations at MGM’s Las Vegas venues, including the MGM Grand and Bellagio, with estimated financial losses ranging from $80 million to $100 million. This incorporates direct impacts on revenue and heightened cybersecurity expenses. The attackers exploited vulnerabilities in service desk operations through social engineering tactics like vishing, which allowed unauthorized system access.

Incident Timeline

  • September 7, 2023: Initial compromise involving an IT vendor linked to Caesars Entertainment and later associated with MGM (source ).
  • September 8, 2023: MGM commenced shutdowns upon infiltration detection (source ).
  • September 10-11, 2023: Public acknowledgment of the breach by MGM (source ).
  • September 12, 2023: Formal disclosure of the incident occurred (source ).

Severity of Impact

The cyberattack caused extensive disruptions across critical infrastructure, including ATMs, slot machines, digital room key systems, and electronic payment systems. Full operational capabilities were not restored for nearly 10 days, leading to estimated daily losses of $4 to $8 million. Consequently, MGM had to implement manual processes, severely impacting guest services and overall performance (source ).

Main Threat Actors

The Scattered Spider group, affiliated with the BlackCat RaaS framework, is noted for advanced social engineering techniques, particularly exploiting service desk vulnerabilities to bypass security such as multifactor authentication. Initial confusion over attribution to BlackCat was clarified when subsequent investigations confirmed Scattered Spider’s central role (source ).

Affected Entities and Data Compromise

The breach affected 29 MGM properties, compromising sensitive customer data including names, driver’s license numbers, and, in some instances, Social Security and passport numbers (source ).

Initial Response and Recovery

MGM’s initial response involved disconnecting compromised Okta sync servers to mitigate the breach’s spread, which inadvertently complicated operational recovery. MGM is prioritizing the resolution of vulnerabilities, enhancing cybersecurity defenses, and reevaluating their Bring Your Own Device policies (source ).

Future Measures

MGM plans to bolster its cybersecurity infrastructure with significant investments aimed at closing identified security gaps, enhancing resilience against future cyber threats (source ).

Incident Overview

Initial Compromise

On September 8, 2023, the cyberattack was initiated using social engineering techniques by the Scattered Spider group. They exploited MGM’s help desk by using vishing to deceptively reset account passwords and compromise multi-factor authentication protocols (source ).

Escalation and System Breaches

Technically, the attackers utilized their access to MGM’s Okta environment to achieve super administrator privileges. This enabled unauthorized Single Sign-Ons and deeper penetration into critical infrastructure, including Microsoft Azure services and over 100 ESXi hypervisors (source ).

Ransomware Deployment

The ransomware was deployed on September 11, 2023, adversely impacting MGM’s operations, particularly disrupting slot machines, ATMs, digital key systems, and payment interfaces, forcing reversion to manual processes (source ).

Operational and Customer Impact

A total of 29 properties experienced significant disruptions including key card systems and slot machine functions. Online services suffered major delays and operational challenges, exacerbating the situation (source ).

Financial Cost and Response

The breach is estimated to have cost MGM Resorts roughly $80 million, encompassing restoration expenses and operational burdens. Long-term, MGM has committed up to $40 million to enhance cybersecurity infrastructure, illustrating a strategic shift (source ).

As a consequence of the breach, MGM faces numerous lawsuits, highlighting the significant legal and regulatory risks posed by such data breaches. These actions underscore compliance concerns with data protection protocols (source ).

Lesson Learned and Recommendations

The attack underscored the necessity for improved defense mechanisms against social engineering and mandates updates in security audits. Focusing on infrastructure security through enhanced identity management, adaptive verification controls, and robust network segmentation is imperative (source ).

Technical Root Cause Analysis

The MGM Grand data breach incident in September 2023 was a significant cyberattack attributed to the Scattered Spider group, affiliated with the ALPHV ransomware collective, resulting in estimated financial losses of $80 million. This section provides a comprehensive technical analysis of the events, focusing on attack vectors, exploited vulnerabilities, and the subsequent impact on MGM’s infrastructure.

Overview of the Attack Chain

The attack followed a well-structured sequence, exploiting social engineering, identity verification weaknesses, and leveraging vulnerabilities in virtualization infrastructure:

  1. Initial Access via Social Engineering: Attackers gained entry into MGM’s systems through social engineering tactics such as vishing (voice phishing). They impersonated a legitimate employee using information aggregated from public sources like LinkedIn, successfully bypassing identity verification protocols at the help desk. This step involved sophisticated manipulation of human factors, highlighting critical flaws in internal security processes.

  2. Privilege Escalation: Post-initial access, the attackers exploited inadequate credential management systems to escalate privileges. The penetration was facilitated by the absence of stringent multi-factor authentication (MFA) requirements for high-privilege accounts. By manipulating weak points within MGM’s identity management framework, attackers achieved administrative access necessary for the deployment of malicious payloads.

  3. Ransomware Deployment: The breach culminated in the execution of a ransomware attack, affecting over 100 ESXi hypervisors. This disruption illustrates the attackers’ proficiency in targeting virtualization environments, leading to extensive outages in critical systems and operational processes.

Technical Vulnerabilities and Misconfigurations

  • Lack of Mature Identity Verification: MGM’s reliance on basic identity verification processes at the help desk allowed attackers to effectively impersonate employees. This highlighted significant internal security deficiencies and a lack of robust employee training to defend against social engineering threats.

  • Inadequate Incident Response Protocols: The hastily executed shutdown of key systems during the breach illustrated insufficient incident response preparedness. This decision inadvertently allowed attackers uninterrupted access and further movement within the network.

  • Absence of Multi-Factor Authentication: The failure to implement MFA for critical account accesses contributed to attacker success in escalating privileges and maintaining persistence within the network.

Architectural and Design Flaws

  • Network Segmentation and Isolation Challenges: The flat network structure permitted lateral movement post-breach, exposing critical system components like ESXi hypervisors. Effective network segmentation might have mitigated some of the attack’s impacts.

  • Dependence on Third-Party Identity Management Systems: The reliance on services like Okta without sufficient oversight and integration security measures increased MGM’s vulnerability to identity and access management failures.

Tools and Techniques Utilized by Attackers

Attackers employed a combination of social engineering tools and advanced exploit scripts to achieve their objectives. Tactics included:

  • Social Engineering: Utilizing psychographic manipulation via phone calls to deceive help desk personnel.

  • Exploitation of ESXi Hypervisors: Leveraging vulnerabilities within the hypervisor environment shows advanced familiarity with virtualization systems.

Security Controls and Standards Unmet

The breach underscores a critical lapse in compliance with established IT security practices:

  • Gaps in Identity and Access Management Protocols: The security framework in place did not align with best practices advocated by leading standards such as NIST and ISO 27001.

  • Inadequate Security Awareness Training: A deficit in comprehensive cyber-awareness programs left employees susceptible to social engineering ploys.

In summary, the MGM Grand breach highlights significant lapses in identity verification, network segmentation, and incident response strategy, which, coupled with a reliance on vulnerable third-party services, facilitated the cyberattack’s success.

Attack Vector and Methodology

Initial Intrusion Method

The initial breach of MGM Resorts in September 2023 was attributed to social engineering tactics, specifically a voice phishing (“vishing”) attack. The attackers masqueraded as employees using personal details sourced from LinkedIn profiles, successfully manipulating the service desk to reset account credentials. This incident exposed significant vulnerabilities in user authentication processes, primarily due to a lack of stringent verification protocols (source ).

Subsequent Strategies and Techniques

Upon gaining access on September 8, 2023, attackers rapidly escalated their privileges, gaining administrative rights in both Okta and Azure environments. This privilege escalation allowed them to deploy ransomware effectively, manipulating conditional access restrictions to lock MGM personnel out of their own systems while maintaining their unauthorized access (source ).

Specific Tools and Techniques

While specific malicious tools used in the attack were not detailed, it was noted that password theft from Okta Agent servers occurred, and ransomware was deployed across more than 100 ESXi hypervisors. These actions disrupted various corporate and customer-facing systems, indicating a sophisticated approach leveraging both social engineering and technical infrastructure exploitation.

Indicators of Compromise (IoCs)

The report does not provide specific Indicators of Compromise such as IP addresses or file hashes. The primary indicator has been the utilization of social engineering to gain access, highlighting an area for improving organizational resilience against such tactics.

Malware Deployed

The malware involved was identified as ALPHV/BlackCat ransomware, which disrupted operations across MGM’s IT landscape, affecting upwards of 100 hypervisor systems. The methods of deployment remain partially described, suggesting the need for further detailed investigation into their technical specifics.

Attack Progression

The attack unfolded in several phases:

  1. Reconnaissance: Attackers gathered employee information from social networking platforms.
  2. Initial Access and Exploitation (September 8, 2023): Achieved through targeted social engineering of service desk operations.
  3. Privilege Escalation: Administrative access was gained over key IT resources, including Okta and Azure.
  4. Ransomware Deployment (September 11, 2023): Initiated after establishing escalated privileges, targeting critical infrastructure.
  5. Containment and Exclusion by Attackers: Enforced through manipulated administrative controls to sustain their system presence.

Innovative or Unexpected Methods

Notably, the attackers leveraged social engineering to manipulate service desk operations, emphasizing human elements over pure technological vulnerability exploitation. This attack illustrates a significant shift towards exploiting corporate identity and access management shortcomings, underscoring the necessity for robust procedural safeguards against social engineering (source ).

Impact Assessment

The cyberattack on MGM Resorts, attributed to the Scattered Spider group in September 2023, resulted in extensive operational disruptions and financial consequences.

Technical Impact

The attack compromised several critical systems at over 29 MGM properties, causing major service disruptions:

  • Slot Machines and ATM Networks: Both were rendered inoperative, affecting casino operations.
  • Digital Room Key Systems: Malfunction led to guest access issues.
  • TV and Phone Services: These were significantly disrupted, impacting guest communications.
  • Internal Networks and Payment Systems: Outages affected overall operations and transactions.

These disruptions forced MGM to revert to manual processes, severely impairing service efficiency (source source source ).

Potential Long-Term Repercussions

Financial and Cybersecurity Impacts

The estimated financial impact of the breach is between $80 million and $100 million, covering operational downtime and recovery costs. Additionally, MGM announced a $40 million investment to enhance its cybersecurity posture to prevent future incidents (source source ).

MGM is currently facing at least 15 class-action lawsuits due to the breach, indicating significant legal challenges ahead. The company also anticipates increased cyber insurance premiums reflecting a heightened risk profile (source ).

Compromised Data Types

Access was gained to potentially sensitive customer and employee data, including:

  • Names, Driver’s License, and Passport Numbers
  • Dates of Birth and Social Security Numbers in some instances
  • Employee Records with personal and financial details

These breaches highlight significant privacy and security concerns, necessitating stronger data protection measures (source ).

Broader Socio-Economic or Industry-Wide Impacts

This attack underscores the vulnerabilities within the hospitality and gaming sectors, prompting a re-evaluation of cybersecurity strategies across the industry. Enhanced emphasis on protection and resilience is critical to prevent similar occurrences (source source ).

Comparison to Similar Incidents

The breach is comparable to the Caesars Entertainment incident, wherein a $15 million ransom was reportedly paid following a similar attack. These cases underscore a troubling rise in targeted attacks within the sector, necessitating robust cybersecurity fortification (source ).

Potential Reputational Damage

MGM Resorts faces potential reputational harm as consumers become wary of data security risks. This could erode customer trust and loyalty, thereby providing competitors with opportunities to capitalize on increased security awareness (source ).

Data Gaps and Uncertainties

There are gaps in the specifics regarding the extent of data compromised, emphasizing a need for further investigation to assess the long-term impact fully. Addressing these uncertainties is essential for rebuilding trust and ensuring security (source ).

Recommendations and Prevention

This section presents targeted recommendations to mitigate similar incidents to the MGM Grand data breach, which occurred in September 2023 due to a cyberattack by the Scattered Spider group. Below are detailed preventive measures along with their technical and operational requirements:


Immediate Technical Controls

  1. Enhance Multi-Factor Authentication (MFA)

    • Implementation: Deploy MFA using hardware tokens or biometric solutions to provide a secondary authentication factor (source ). Integration must support all existing systems, ensuring compatibility with platforms such as Okta for identity management.
    • Cost Estimate: Approximately $10,000 to $30,000 depending on the scale and technological adoption.
    • Rationale: This measure mitigates risks from identity-based attacks by requiring additional layers of verification beyond simple password authentication.
  2. Deploy Advanced Threat Detection Solutions

    • Implementation: Invest in Endpoint Detection and Response (EDR) and Security Information and Event Management (SIEM) systems to monitor anomalies and detect breaches proactively. AI-driven tools should enhance capability for real-time threat identification (source ).
    • Technical Requirements: Systems must integrate seamlessly with existing network infrastructure and support continuous monitoring with regular updates.
    • Rationale: The existing detection systems were insufficient, allowing prolonged unauthorized access, which could have been mitigated with advanced monitoring.

Process and Policy Updates

  1. Regular Security Awareness Training

    • Policy Update: Conduct periodic, comprehensive training on social engineering tactics (vishing, phishing), supported by simulated attack exercises to reinforce learning (source ).
    • Implementation Strategy: Deploy training every quarter; refine material based on emerging threat landscapes.
    • Rationale: Enhanced awareness can reduce susceptibility to social engineering, a vector exploited in the breach.
  2. Comprehensive Incident Response Plan

    • Implementation: Develop and frequently update an incident response plan tailored to scenarios similar to the breach, involving roles, actions, and communication strategies (source ). Include regular drills for preparedness validation.
    • Rationale: Swift, organized response reduces operational disruption and damage in case of incidents.

Long-Term Infrastructure Changes

  1. Adopt Zero Trust Security Model

    • Implementation: Embrace a Zero Trust framework, ensuring no implicit trust within the network. Mandate strict identity verification with continuous authentication protocols and network segmentation (source ).
    • Prerequisites: Evaluate current infrastructure for necessary upgrades; create roadmaps to achieve desired security postures.
    • Rationale: By implementing strict access controls, potential damages from compromised credentials are minimized.
  2. Timeline and Milestones:

    • Begin implementing Immediate Technical Controls within the next 3 months.
    • Schedule Process/Policy Updates concurrently, with completion targeted within 6 months.
    • Aim to accomplish Long-Term Infrastructure Changes within a 12 to 18-month period.

By adhering to these comprehensive strategies, MGM Resorts and similar entities can fortify their defenses, reducing the likelihood of reoccurrence of breaches exploiting similar vectors.

Conclusion

The MGM Grand cyberattack in September 2023, attributed to the Scattered Spider group, highlights significant deficiencies in cybersecurity practices within the hospitality sector. This breach, costing an estimated $80 million, underscores critical vulnerabilities in employee verification systems and the reliance on insecure personal data for authentication. This necessitates a comprehensive reassessment of identity management frameworks, especially for service desks targeted by social engineering attacks (source ).

Lessons Learned for Future Resilience

Enhanced Security Protocols

The breach demonstrates the critical need for enhanced multi-factor authentication (MFA), especially for sensitive systems such as Okta and Azure. Implementing robust MFA solutions can mitigate unauthorized access risks stemming from compromised credentials (source ).

Employee Education and Vigilance

Comprehensive training programs targeting social engineering tactics, including phishing and vishing, are vital. Empowering employees to detect and counter such methods is crucial, highlighting the gap between technological defenses and the human element in cybersecurity (source ).

Steps for Improving Security Posture

Advanced Threat Detection

Investing in sophisticated threat detection systems that identify abnormal access patterns can significantly enhance early detection capabilities, aiding in rapid threat response (source ).

Incident Response Enhancement

Developing robust incident response playbooks is vital for effective breach management, ensuring key procedures are followed to minimize damage and expedite recovery (source ).

The incident illustrates a trend towards sophisticated, coordinated cyberattacks, leveraging social engineering and ransomware tactics. The reported connections to ALPHV (BlackCat) highlight the increasing complexity of organized cybercrime (source ).

Positive Outcomes and Security Improvements

Despite the challenges, the breach presents opportunities for significant improvements in cybersecurity strategies within MGM and the broader industry. Anticipated advancements include increased cybersecurity investments, sophisticated monitoring systems, and enhanced collaboration with cybersecurity experts (source ).

Areas Lacking Data

The breach leaves critical questions unanswered, such as specific plans for the new cybersecurity investments and the long-term impact on MGM’s reputation. Addressing these gaps is crucial for developing robust security strategies (source ).

This report was machine-generated with PlanAI using the following sources:

Invariant analysis

InvariantEffectivenessConf.Explanation
Mandatory Hardware Second FactorMediumThe initial access step relied on vishing the service desk to 'reset account passwords and compromise multi-factor authentication protocols,' i.e., socially engineering the help desk into re-enrolling MFA for the attacker. A hardware-based second factor cannot be trivially reset over a phone call the way a software/SMS/TOTP factor can \u2014 it typically requires physical possession or a hardware provisioning process, which vishing alone does not achieve. This would have prevented the attackers from completing authentication even after obtaining/resetting the password, stopping the initial compromise before privilege escalation into Okta/Azure and the subsequent ransomware deployment could occur.
Positive Execution ControlMediumThe attack culminated in deployment of ALPHV/BlackCat ransomware across more than 100 ESXi hypervisors (September 11, 2023), causing the disruption of slot machines, ATMs, digital key systems, and payment interfaces at 29 properties. Positive execution control on production systems (including hypervisors) would prevent this non-allow-listed ransomware binary from executing, blocking the primary damaging objective of the attack even though the initial vishing-based access and Okta/Azure privilege escalation (which largely abused legitimate administrative tools/credentials rather than executing new malware) would not be stopped by this control.
Egress ControlMediumThe attack chain's exfiltration of PII (names, SSNs, driver's license numbers) to attacker-controlled infrastructure would require an outbound connection not on any legitimate allow list, so egress control would block that channel. However, the attackers gained privileged access via Okta/Azure through stolen credentials and used that legitimate, authenticated administrative access to deploy ALPHV/BlackCat ransomware across 100+ ESXi hypervisors; this deployment does not necessarily depend on the compromised hosts making new outbound connections to attacker infrastructure, so the ransomware encryption and resulting operational disruption (slot machines, ATMs, key cards, payment systems across 29 properties) would likely still occur. This is a partial containment: exfiltration is blocked but the material ransomware impact still happens.
Supply Chain AgingHighThe report describes no involvement of open-source software packages, third-party dependencies, or software supply chain compromise anywhere in the attack chain (initial vishing, Okta privilege escalation, ESXi ransomware deployment). This invariant does not interact with the attack at all.

Scored in assets/invariants/MGM_Grand_September_2023_final.yaml — the same rows the leaderboard counts.

Read the invariant that would have stopped this

Comments

Now playing Bandcamp