Ransomware
BleepingComputer / Morphisec / CSHub
Primary Source βIncident Details
Scattered Spider (UNC3944) used LinkedIn to identify MGM employee, called IT helpdesk impersonating them to get Okta/Azure admin access. Waited 2 days then launched ransomware against 100+ ESXi hypervisors on Sept 11. Slot machines, digital room keys, reservation systems offline for ~10 days. ALPHV/BlackCat claimed 6TB data exfiltrated. MGM refused to pay. $100M Q3 2023 loss. Customer PII including SSNs exposed. Five Scattered Spider members charged in 2024.
Technical Details
- Initial Attack Vector
- CWE-1391: Use of Weak Credentials (social engineering via LinkedIn identity theft + vishing helpdesk to bypass Okta MFA)
- Vendor / Product
- MGM Resorts enterprise systems / Okta / VMware ESXi
- Malware Family
- ALPHV/BlackCat
Timeline
- 2023-09-08 Breach occurred
- 2023-09-11 Publicly disclosed
- 2023-10-20 Customers notified