Desk live·
ForensicPost
Ransomware/Availability/File 23-0911

MGM Resorts Put the Cost of Its September Attack at About $100 Million

Slot machines, room keys and reservation systems went down across MGM properties from 11 September 2023. The company later reported the financial impact in a securities filing and confirmed that customer data from before March 2019 had been taken.

Constructed geometry · not a chart of case data
JurisdictionUSALas Vegasthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetMGM Resorts International
ActorScattered Spider
S. Rosler10 min readConfidence: high2 sources reviewed

MGM Resorts International took systems offline from 11 September 2023 following a cyberattack, with the disruption running across Las Vegas properties for several days. The company subsequently reported the financial impact in a securities filing, and reporting on that filing put the figure at around $100 million.

MGM also stated that attackers obtained personal information belonging to customers who transacted with the group before March 2019.

The Loss Was Availability, Not Records

The pre-2019 qualifier on the data is doing real work. The bulk of the reported cost is not a records loss at all — it is casino floors, booking systems and hotel operations not functioning during a period MGM could otherwise sell.

The corpus files availability harm separately from data harm for exactly this reason, at 24-1231. A breach notification counts records. It has no field for a fortnight of manual check-in.

Two Companies, Two Decisions

Caesars Entertainment disclosed an intrusion in the same month, reported as social engineering against an outsourced IT support provider, and reporting stated that Caesars paid. MGM did not pay and absorbed the outage.

It is the closest thing to a controlled comparison this database holds, and it does not resolve the payment question. One company bought a shorter outage; the other bought a $100 million line item and a set of facts it could publish. Both were extorted successfully.

The Route In Was A Conversation

Reporting on the MGM intrusion described social engineering against a help desk, with the activity attributed by researchers to the cluster tracked as Scattered Spider. This desk records that attribution as reported rather than established.

What is not in dispute is the technique class. The corpus went on to file the same sequence at 25-0806 against SaaS tenants, at 25-0806b against Workday and at 25-1208 against university development offices. A help desk exists to restore access to people who cannot prove who they are; that is the function, and it is also the hole.

How we reported this

Built on reporting of MGM Resorts’ securities filing and on contemporaneous coverage of the outage and the subsequent data disclosure. The $100 million figure is the company’s own reported estimate of financial impact, not an independent assessment, and it is a cost to MGM rather than a measure of harm to anyone else. The attribution to Scattered Spider is researcher attribution reported at the time; this desk has not independently assessed it and the analysis does not depend on it. The reported Caesars payment is reported as such — no payment is confirmed by this desk. No indicators are reproduced. Graded high on the outage, the cost figure and the data disclosure. Corrections: corrections@forensicpost.com.

Sources
  1. MGM Resorts says cyberattack cost $100 million, resulted in theft of customer infoThe Record
  2. Hackers claim MGM cyberattack as outage drags into fourth dayTechCrunch
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary