Executive Summary
In late summer and early fall 2023, Las Vegas casinos MGM Resorts and Caesars Entertainment suffered major cyberattacks conducted by the Scattered Spider threat group, including at least one 17-year-old suspect. Attackers gained network access via social engineering and lateral movement, ultimately deploying BlackCat/ALPHV ransomware. The incidents led to severe operational disruption, significant financial losses exceeding $100 million for MGM, a $15 million ransom paid by Caesars, and exposure of sensitive customer and employee data. Law enforcement identified and apprehended one teenage perpetrator, who was later released to parental custody pending trial.
This high-profile case highlights the growing trend of sophisticated, identity-driven ransomware attacks launched by younger, tech-savvy threat actors and hacking collectives. It underscores the urgent need for organizations to close internal security gaps, improve zero trust posture, and address the challenges of compliance amid increasingly aggressive and disruptive ransomware campaigns.
Why This Matters Now
This incident demonstrates how even major enterprises with substantial resources remain exposed to advanced ransomware operations using social engineering and lateral movement. The involvement of minors in highly organized attacks, coupled with significant financial fallout and compliance risks, emphasizes the need for urgent improvements in network segmentation, access controls, and rapid incident response capabilities.
Attack Path Analysis
The attacker, associated with Scattered Spider, first gained initial access to the casino networks, likely leveraging social engineering or exposed credentials. After entry, they escalated privileges within cloud or hybrid environments through further access abuse. Using the gained foothold, they performed lateral movement to access sensitive systems such as customer data and administrative interfaces. Command and control channels were established for remote orchestration and control, likely using covert or encrypted channels. Sensitive data was then exfiltrated, and ransomware was deployed to disrupt operations, encrypt files, and extort the victims.
Kill Chain Progression
Initial Compromise
Description
Attacker gained network access, likely via social engineering and/or stolen credentials targeting casino staff and IT administrators.
Related CVEs
CVE-2023-0669
CVSS 7.2A pre-authentication command injection vulnerability in Fortra's GoAnywhere MFT allows remote attackers to execute arbitrary code.
Affected Products:
Fortra GoAnywhere MFT – < 7.1.2
Exploit Status:
exploited in the wildCVE-2019-7481
CVSS 9.8An SQL injection vulnerability in SonicWall Secure Remote Access devices allows remote attackers to execute arbitrary SQL commands.
Affected Products:
SonicWall Secure Remote Access – 8.0.0.0-8.0.0.4
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Valid Accounts
Phishing
Command and Scripting Interpreter
Data Encrypted for Impact
Data from Local System
Remote Services
Exfiltration Over C2 Channel
Application Layer Protocol
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – User Authentication for All System Components
Control ID: 8.2.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Article 5
NIS2 Directive – Cybersecurity Risk Management and Reporting
Control ID: Article 21
CISA ZTMM 2.0 – User and Credential Hygiene
Control ID: Identity - Protect: 1.3
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Gambling/Casinos
Direct ransomware targeting with $100M+ damages demonstrates critical vulnerability to sophisticated network intrusions, requiring enhanced east-west traffic security and zero trust segmentation.
Financial Services
Cryptocurrency theft and extortion tactics expose payment processing vulnerabilities, necessitating improved egress security, threat detection, and encrypted traffic protection for digital assets.
Hospitality
Casino resort operations disruption reveals hospitality sector exposure to ransomware affecting guest services, requiring multicloud visibility and anomaly detection for operational continuity.
Computer/Network Security
Scattered Spider's sophisticated attack methods highlight need for enhanced inline IPS capabilities, cloud native security fabrics, and Kubernetes security against advanced persistent threats.
Sources
- Teen suspected of Vegas casino cyberattacks released to parentshttps://www.bleepingcomputer.com/news/security/teen-suspected-of-vegas-casino-cyberattacks-released-to-parents/Verified
- Data breach at MGM Resorts expected to cost casino giant $100 millionhttps://apnews.com/article/087726961b5366065b6231d1d223b4ebVerified
- Casino giant Caesars Entertainment reports cyberattack; MGM Resorts says some systems still downhttps://apnews.com/article/3f7f80d0d200e9f26a2efa88bc5a6862Verified
- BlackCat Ransomware Group Exploits GoAnywhere Vulnerabilityhttps://www.at-bay.com/articles/blackcat-ransomware-group-exploits-goanywhere-vulnerability/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust network segmentation, robust east-west traffic controls, encrypted communication, and egress policy enforcement would have limited the attacker’s ability to move laterally, establish persistent C2, and prevent data exfiltration and ransomware impact across hybrid casino environments.
Control: Cloud Firewall (ACF)
Mitigation: Reduced attack surface and blocked unauthorized inbound/egress attempts.
Control: Multicloud Visibility & Control
Mitigation: Improved detection of anomalous privilege changes and access escalations.
Control: Zero Trust Segmentation
Mitigation: Blocked unauthorized lateral movement and minimized breach blast radius.
Control: Inline IPS (Suricata)
Mitigation: Real-time detection and disruption of known C2 protocols and remote access tools.
Control: Egress Security & Policy Enforcement
Mitigation: Prevents data exfiltration and unauthorized outbound communications.
Rapid detection of ransomware behaviors and automated incident response.
Impact at a Glance
Affected Business Functions
- Reservations
- Casino Operations
- Payment Processing
Estimated downtime: 10 days
Estimated loss: $100,000,000
Personal information, including names, contact details, and identification numbers of customers, was compromised.
Recommended Actions
Key Takeaways & Next Steps
- • Implement zero trust network segmentation and microsegmentation across all east-west traffic to block lateral movement.
- • Enforce strict egress filtering and policy-based controls to prevent unauthorized outbound data transfer and C2 channels.
- • Deploy centralized multicloud visibility and real-time anomaly detection for early identification of privilege escalation or malware activity.
- • Utilize inline cloud-native IPS and cloud firewall controls to detect, block, and contain network-based exploits and known ransomware signatures.
- • Regularly review and update identity management, least privilege access, and workload runtime controls to minimize attack surface and privilege abuse opportunities.



