MGM Resorts outage continues as FBI launches investigation

Hacker
Image Credit: Geralt / Pixabay (Image credit: Image Credit: Geralt / Pixabay)

A cyberattack attributed to hacker group Scattered Spider has caused an outage across MGM Resorts International’s computer systems, affecting some casino and hotel computer systems including the company’s website.

An error message on the website reads: “The MGM Resorts website is currently unavailable. We apologize for the inconvenience.” Users are instead directed to mobile applications and third-party services to access certain parts of the company’s offerings.

The “cybersecurity issue,” which has been ongoing since September 11, remains under investigation with even the FBI stepping in.

Major MGM outage being investigated

The FBI confirmed on September 13 that it had started investigating the incident (via Reuters), while MGM posted to X earlier this week: “Our investigation is ongoing and we are working diligently to determine the nature and scope of the matter.”

MGM’s website is currently directing restaurant customers to make reservations via its app, and for resident artist, production show, or attraction bookings to be made via Ticketmaster. Customers seeking UFC, Las Vegas Aces, Vegas Golden Knights, and Arena-based concert events are being told to use AXS.

Mandiant Intelligence’s CTO, Charles Carmakal, spoke on LinkedIn about the group, also known as UNC3944, calling it “one of the most prevalent and aggressive threat actors impacting organizations in the United States today.”

Carmakal said the cybersecurity company would publish more details about the group soon.

In the meantime, Reuters referred to a previous Crowdstrike blog post offering insight into the group’s activity: “Identified by analysts last year, this group uses social engineering to lure users into giving up their login credentials or one-time-password (OTP) codes to bypass multi-factor authentication.”

More broadly, a Bloomberg report citing four people familiar with the matter stated that the same group was responsible for a Caesars Entertainment Inc. breach just a few weeks ago. Another article suggests that Caesars paid “tens of millions” to the hackers responsible and has plans to “disclose the cyberattack in a regulatory filing imminently.” 

More from TechRadar Pro

Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
A close-up of an interent search bar with 'http://ww' visible
Major website hijacking scam sees over 35,000 sites attacked, redirected to gambling sites, so be on your guard
Red padlock open on electric circuits network dark red background
Newspaper printing across US hit after Lee Enterprises says “cybersecurity event” disrupted operations
marriott
FTC orders Marriott and Starwood to boost cybersecurity following major incidents
Casio logo
Casio’s online store hit by bogus credit card stealing checkout form
The British Museum main entrance
British Museum forced to partly close following cyberattack by ex-worker
Ransomware
Millions of hotel guest reservations leaked in Otelier data breach
Latest in Security
Lock on Laptop Screen
Data breach at Pennsylvania education union potentially exposes 500,000 victims
Spyware
Stalkerware data breach potentially hits over 2 million users, including thousands of Apple devices
An American flag flying outside the US Capitol building against a blue sky
Five Eyes "cannot replace US intel in Ukraine", claims former US Cyber Command Chief
Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration.
Criminals are using a virtual hard disk image file to host and distribute dangerous malware
WordPress on a laptop
Over 20,000 WordPress sites hit by damaging malware campaign
Trojan
WhatsApp patches security flaw which let hackers install spyware
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Friday, March 21 (game #1152)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Friday, March 21 (game #383)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Friday, March 21 (game #649)
The ASSC Assassin's Creed collection.
The Assassin's Creed x Anti Social Social Club drop includes gaming merch that I wouldn't be embarrassed to wear
Lock on Laptop Screen
Data breach at Pennsylvania education union potentially exposes 500,000 victims
Spyware
Stalkerware data breach potentially hits over 2 million users, including thousands of Apple devices