MGM Resorts security incident

Scattered Spider; vished IT help desk after identifying an employee on LinkedIn. 10-day outage of slot machines, hotel key cards, reservations.

Last modified

Summary

  • Environment: Hospitality/Casino
  • Operational impact: 10-day outage of slot machines, hotel key cards, reservations
  • Financial impact: approximately $100M
  • Record status: Developing record. Reviewed September 19, 2026; updated as evidence emerges.

What happened

In 2023, MGM Resorts experienced an incident in its hospitality/casino environment. The retained source describes the attack path as follows: Scattered Spider; vished IT help desk after identifying an employee on LinkedIn. [1]

The documented consequence was: 10-day outage of slot machines, hotel key cards, reservations. [1]

Impact

  • Documented impact: 10-day outage of slot machines, hotel key cards, reservations. [1]
  • Documented financial consequence: approximately $100M. [1]

Threat Group & Attack Vector

The retained source describes the attack path as follows: Scattered Spider; vished IT help desk after identifying an employee on LinkedIn. The canonical record does not add intrusion steps beyond those supported by the source. [1]

Actors

  • Scattered Spider — identified in the supported attack description. [1]

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

The retained source describes containment action intended to limit further access or disruption. [1]

This account is bounded to MGM Resorts International Form 8-K. Details absent from that evidence are left unresolved rather than inferred. [1]