Ransomware

BleepingComputer / Morphisec / CSHub

πŸ“… 2023-09-08 🏒 MGM Resorts enterprise systems / Okta / VMware ESXi 🦠 ALPHV/BlackCat
Primary Source β†—

Incident Details

Scattered Spider (UNC3944) used LinkedIn to identify MGM employee, called IT helpdesk impersonating them to get Okta/Azure admin access. Waited 2 days then launched ransomware against 100+ ESXi hypervisors on Sept 11. Slot machines, digital room keys, reservation systems offline for ~10 days. ALPHV/BlackCat claimed 6TB data exfiltrated. MGM refused to pay. $100M Q3 2023 loss. Customer PII including SSNs exposed. Five Scattered Spider members charged in 2024.

Technical Details

Initial Attack Vector
CWE-1391: Use of Weak Credentials (social engineering via LinkedIn identity theft + vishing helpdesk to bypass Okta MFA)
Vendor / Product
MGM Resorts enterprise systems / Okta / VMware ESXi
Malware Family
ALPHV/BlackCat

Timeline

  1. 2023-09-08 Breach occurred
  2. 2023-09-11 Publicly disclosed
  3. 2023-10-20 Customers notified