logo

Would Have, Could Have, Should Have: Dissecting the 2023 MGM Hack

ID: 1e2e23cb-9fa6-5dd1-ac3a-5351b08594f6

STIX ID: report--1e2e23cb-9fa6-5dd1-ac3a-5351b08594f6

Feed Name: Deep Instinct Blog

Threat Score
88/100

Date Published: 2024-08-01

Date Updated: 2026-04-27

Author: Carl Froggett

...
...

In late 2023 the AlphV subgroup ScatteredSpider executed a high-impact ransomware campaign against MGM Resorts by using LinkedIn-based reconnaissance and voice impersonation to trick the IT help desk, obtain elevated credentials, deploy sniffers, exfiltrate admin credentials (Azure, Windows, Okta), and deliver ransomware to approximately 100 ESXi hypervisors—disrupting reservations, gaming systems, digital room access and exposing customer PII; the attack reportedly cost nearly $100M and the document frames the incident to argue for prevention-first security controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.