Who Hacked MGM Casino and How It Happened

In September 2023 the MGM Resorts network experienced a major breach that shut down slot floors, digital wallets and loyalty programs across multiple properties. The attack was later claimed by the Scattered Spider group, also known as UNC3944. Initial access reportedly started with a help-desk vishing call that tricked staff into resetting credentials for an internal VPN. Once inside, the intruders used social-engineering tactics to reach the domain controller and deploy ransomware. The outage lasted roughly ten days and produced an estimated $100 million revenue loss.

Regulators and cybersecurity firms later published timelines showing that multi-factor authentication was not enforced on every remote session. This single gap allowed attackers to move laterally without triggering alerts. MGM’s own post-incident report confirmed that network segmentation between hotel and gaming systems was incomplete, giving the threat actors access to point-of-sale terminals and slot accounting servers simultaneously.

Timeline of the MGM Breach

10 Sept – Initial vishing call succeeds
11 Sept – Ransomware deployed across domain
12 Sept – MGM takes systems offline
21 Sept – Partial restoration of slot floor

The first suspicious login occurred on 10 September 2023. Within hours the attackers had mapped Active Directory groups and located backup repositories. By the next morning ransomware binaries were staged on more than 100 hosts. MGM’s security operations center noticed unusual Kerberos ticket-granting requests around 02:00 local time, but the team could not isolate segments fast enough to prevent domain-wide encryption.

Casino note: live tables, slots and cashback change often — recheck terms.

Lessons for Online Casino Players

"Look at payment speed and table limits, not only the headline bonus."
Lesson: that even large operators can be forced

The MGM incident is a reminder that even large operators can be forced offline. Players should keep copies of transaction IDs and maintain withdrawal requests on at least two separate casinos. During prolonged outages, alternative sites with instant KYC approval become valuable. Operators that use segregated wallet technology and third-party game providers often recover faster because only the front-end skin is affected.

How to Verify an Operator’s Security Today

SOC-2 reports. Check that remote-admin portals enforce

Look for published penetration-test summaries and SOC-2 reports. Check that remote-admin portals enforce phishing-resistant MFA such as hardware keys. Confirm that game providers run on separate infrastructure from the operator’s CRM so a single breach cannot halt both deposits and gameplay.

Frequently Asked Questions

Was customer financial data stolen?

Investigators found no evidence that credit-card numbers or bank details were exfiltrated. The main data accessed included loyalty profiles and hotel reservation records.

How long should I keep withdrawal records after a breach?

Regulators recommend retaining transaction receipts for at least 90 days in case an operator needs to reconcile balances after restoration.

Can I still claim MGM bonuses during recovery?

Most bonus codes tied to the MGM network were paused. Players were advised to check the promotions page daily once services returned.

Did the hack affect online MGM sportsbooks?

Yes. Both retail and online sportsbooks were offline for ten days, and pending bets were voided or refunded according to house rules.