MGM Resorts International took systems offline from 11 September 2023 following a cyberattack, with the disruption running across Las Vegas properties for several days. The company subsequently reported the financial impact in a securities filing, and reporting on that filing put the figure at around $100 million.
MGM also stated that attackers obtained personal information belonging to customers who transacted with the group before March 2019.
The Loss Was Availability, Not Records
The pre-2019 qualifier on the data is doing real work. The bulk of the reported cost is not a records loss at all — it is casino floors, booking systems and hotel operations not functioning during a period MGM could otherwise sell.
The corpus files availability harm separately from data harm for exactly this reason, at 24-1231. A breach notification counts records. It has no field for a fortnight of manual check-in.
Two Companies, Two Decisions
Caesars Entertainment disclosed an intrusion in the same month, reported as social engineering against an outsourced IT support provider, and reporting stated that Caesars paid. MGM did not pay and absorbed the outage.
It is the closest thing to a controlled comparison this database holds, and it does not resolve the payment question. One company bought a shorter outage; the other bought a $100 million line item and a set of facts it could publish. Both were extorted successfully.
The Route In Was A Conversation
Reporting on the MGM intrusion described social engineering against a help desk, with the activity attributed by researchers to the cluster tracked as Scattered Spider. This desk records that attribution as reported rather than established.
What is not in dispute is the technique class. The corpus went on to file the same sequence at 25-0806 against SaaS tenants, at 25-0806b against Workday and at 25-1208 against university development offices. A help desk exists to restore access to people who cannot prove who they are; that is the function, and it is also the hole.
Built on reporting of MGM Resorts’ securities filing and on contemporaneous coverage of the outage and the subsequent data disclosure. The $100 million figure is the company’s own reported estimate of financial impact, not an independent assessment, and it is a cost to MGM rather than a measure of harm to anyone else. The attribution to Scattered Spider is researcher attribution reported at the time; this desk has not independently assessed it and the analysis does not depend on it. The reported Caesars payment is reported as such — no payment is confirmed by this desk. No indicators are reproduced. Graded high on the outage, the cost figure and the data disclosure. Corrections: corrections@forensicpost.com.