Executive Summary
In late 2023, Las Vegas casinos suffered major cyberattacks attributed to the Scattered Spider threat group, resulting in widespread operational disruption. The attacks targeted MGM Resorts International and Caesars Entertainment, leveraging sophisticated social engineering and phishing tactics to gain network access, move laterally, and ultimately extort ransom payments. MGM reported losses exceeding $100 million, while Caesars reportedly paid $15 million to mitigate risks. In June 2024, a local teenage suspect was arrested in connection to these events, highlighting the involvement of young, native English-speaking cybercriminals and a broader international law enforcement response.
This incident exemplifies the increasing prevalence of highly organized, technology-savvy ransomware and extortion campaigns that rely on social engineering and identity-centric attack vectors. Organizations across industries face rising risks as threat groups adopt coordinated, multifaceted tactics to exploit internal and hybrid cloud environments.
Why This Matters Now
This case demonstrates how modern ransomware crews like Scattered Spider successfully target high-value, complex environments using social engineering and lateral movement to bypass traditional security. The trend of involving minors and international collaboration elevates regulatory urgency, especially as sophisticated attacks increasingly exploit identity-based and east-west vulnerabilities.
Attack Path Analysis
The attackers initiated their campaign with targeted social engineering, likely phishing and impersonation, to gain access to casino networks. After gaining initial access, they escalated privileges to move laterally within internal cloud and on-prem environments. Leveraging east-west network paths, the group expanded access across systems to consolidate control. They established command and control channels to maintain persistent connectivity and orchestrate ransomware deployment. Sensitive data was then exfiltrated via covert or sanctioned egress channels, followed by ransomware encryption and business disruption that resulted in substantial financial losses and extortion demands.
Kill Chain Progression
Initial Compromise
Description
Attackers used spear-phishing and social engineering to obtain valid employee credentials and establish footholds within the casino network.
Related CVEs
CVE-2015-2291
CVSS 7.8A vulnerability in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service (system crash) via a crafted application.
Affected Products:
Intel Ethernet diagnostics driver for Windows – before 1.3.1.0
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Phishing
Valid Accounts
Brute Force
Command and Scripting Interpreter
System Binary Proxy Execution
Data Encrypted for Impact
Inhibit System Recovery
Service Stop
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Access Control Measures
Control ID: 8.3.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT-related Incident Management
Control ID: Art. 10
CISA Zero Trust Maturity Model 2.0 – Identity Verification and Access Controls
Control ID: Identity Pillar - Access Management
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Gambling/Casinos
Direct ransomware/extortion attacks targeting casino operations resulted in $100M+ losses, requiring enhanced zero trust segmentation and threat detection capabilities.
Hospitality
Casino hospitality services face similar social engineering vulnerabilities, necessitating improved egress security and anomaly detection to prevent operational shutdowns.
Financial Services
Scattered Spider's social engineering tactics threaten financial institutions requiring encrypted traffic protection and multicloud visibility for payment processing systems.
Airlines/Aviation
Recent attacks on Hawaiian Airlines and WestJet demonstrate aviation sector vulnerability to extortion campaigns requiring enhanced east-west traffic security.
Sources
- Las Vegas police arrest minor accused of high-profile 2023 casino attackshttps://cyberscoop.com/las-vegas-teenager-arrested-casino-attacks-scattered-spider/Verified
- Scattered Spider (Wikipedia)https://en.wikipedia.org/wiki/Scattered_SpiderVerified
- Cybersecurity issue prompts computer shutdowns at MGM Resorts properties across UShttps://apnews.com/article/06de044bdf1880af2a8bce1a38c986eeVerified
- 2 Casino Ransomware Attacks: Caesars Paid, MGM Did Nothttps://www.forbes.com/sites/suzannerowankelleher/2023/09/14/2-casino-ransomware-attacks-caesars-mgm/Verified
- MGM and Caesars hackers: who are they?https://cybernews.com/editorial/mgm-caesars-explained-scattered-spider/Verified
- BlackCat (cyber gang) (Wikipedia)https://en.wikipedia.org/wiki/BlackCat_%28cyber_gang%29Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Comprehensive Zero Trust segmentation, workload isolation, encrypted traffic controls, threat detection, and strong egress policy enforcement would have significantly constrained attacker movement, detected anomalous activities, and blocked both lateral spread and exfiltration throughout the attack chain.
Control: Multicloud Visibility & Control
Mitigation: Early detection of unauthorized access attempts via centralized policy and traffic observability.
Control: Zero Trust Segmentation
Mitigation: Identity-based, least-privilege policies constrain access, limiting breakout risk.
Control: East-West Traffic Security
Mitigation: Real-time internal traffic inspection and policy enforcement block unauthorized lateral movement.
Control: Threat Detection & Anomaly Response
Mitigation: Automated detection and alerting of unusual threat behaviors and C2 traffic.
Control: Egress Security & Policy Enforcement
Mitigation: Granular outbound filtering blocks unauthorized data transfers and egress attempts.
Unified real-time enforcement and distributed policy minimize blast radius and limit compromise.
Impact at a Glance
Affected Business Functions
- Reservations
- Casino Operations
- Payment Processing
- Customer Loyalty Programs
Estimated downtime: 10 days
Estimated loss: $100,000,000
Personal information of customers, including Social Security numbers and driver's license numbers, was compromised.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust network segmentation and least-privilege access policies across all cloud and hybrid infrastructure.
- • Establish continuous east-west traffic inspection and internal segmentation to prevent and detect lateral movement.
- • Enforce egress filtering with granular DNS and FQDN controls to block unauthorized data transfers and command & control.
- • Deploy real-time anomaly and threat detection to enable rapid response to suspicious authentication or remote access attempts.
- • Ensure comprehensive workload isolation, encryption in transit, and centralized multicloud visibility to reduce exposure and increase incident detection speed.



