MGM Casinos and Resorts Breach

I’m sure you’ve heard that MGM Casinos and Resorts got hit hard by a cyberattack. Hackers were able to bring the entertainment giant to its knees.

And how did this massive event start? With a seemingly innocent ten-minute phone call. Reports indicate that their IT support desk personnel were persuaded to give a member of the “Scattered Spider” hacker group administrative access. This U.S. and Canada based group of young hackers is known for using social engineering to psychologically manipulate victims to get what they want. 

Once they access a system, this group is known for stealing data such as business documents, personal information such as social security numbers, and client and customer data for use in double extortion. They then deploy ransomware to render data and systems unusable.

In the case of the MGM attack, they were able to shut down most systems you would find in casinos and resorts. These included everything from ATM’s, electronic gaming systems, hotel door locks, and even the in-room televisions. The front desk could not settle bills for guests checking out or check reservations for incoming guests.

The Lotus team does provide help desk support for many companies. It has long been a priority to implement systems to prevent our team from being phished. We offer on-going security training to our team and role-play in building awareness of the tactics used by bad actors.

You should always be suspicious of out of the blue or urgent requests, even over the phone. Remember we will never ask you to have access to go to a website to get access to your computer for support or ask you to share multifactor codes. Finally, be cautious about emails that have attachments or links in them.