{"id":20834,"date":"2023-10-13T05:57:46","date_gmt":"2023-10-13T05:57:46","guid":{"rendered":"https:\/\/www.insurancejournal.com\/?p=744088"},"modified":"2023-10-13T05:57:46","modified_gmt":"2023-10-13T05:57:46","slug":"mgm-hackers-waited-for-days-before-issuing-their-ransom-demands","status":"publish","type":"post","link":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/2023\/10\/13\/mgm-hackers-waited-for-days-before-issuing-their-ransom-demands\/","title":{"rendered":"MGM Hackers Waited for Days Before Issuing Their Ransom Demands"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.insurancejournal.com\/app\/uploads\/2023\/10\/MGM-las-vegas-Bloomberg-580x387.jpg\"><\/p>\n<div><img decoding=\"async\" src=\"https:\/\/www.insurancejournal.com\/app\/uploads\/2023\/10\/MGM-las-vegas-Bloomberg-scaled.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<ul class=\"nav nav-tabs tabs tabs-entry\">\n<li class=\"active\"><a href=\"https:\/\/www.insurancejournal.com\/news\/national\/2023\/10\/13\/744088.htm\">Article<\/a><\/li>\n<li><a href=\"https:\/\/www.insurancejournal.com\/news\/national\/2023\/10\/13\/744088.htm?comments\" rel=\"nofollow\">0 Comments<\/a><\/li>\n<\/ul>\n<div class=\"article-content clearfix\">\n<p class=\"bloomberg\">MGM Resorts International Chief Executive Officer Bill Hornbuckle chose not pay a ransom to hackers who broke into his casino chain\u2019s computer system because they didn\u2019t ask for money until well after the company discovered the attack.<\/p>\n<p>The intruders moved through MGM\u2019s systems for several days before sending a ransom note, Hornbuckle said in an interview Tuesday. The attack was so far along and the company had already begun rebuilding systems that were pulled offline that Hornbuckle chose to not even respond to the hackers.<\/p>\n<div class=\"bzn bzn-sized bzn-intext\">\n<ins data-revive-zoneid=\"79\" data-revive-topics=\"cyber\" data-revive-companies data-revive-block=\"1\" data-revive-id=\"36eb7c2bd3daa932a43cc2a8ffbed3a9\"><\/ins> <\/div>\n<p>\u201cI\u2019d love to tell you there was this, you know, \u2018a jump on a white horse moment and devil be damned \u2014 we\u2019re not paying these bastards,&#8217;\u201d Hornbuckle said. \u201cThe reality is because we caught this so early and we were on them.\u201d<\/p>\n<p>MGM, the largest owner of casinos on the Las Vegas Strip, estimates the hack began on the evening of Sept. 7. The company tried to shut down systems before the attackers could steal any data, but they ultimately got into the corporate Domain Name System (DNS) layer, which helps run all of a company\u2019s applications and can be used to deploy malware.<\/p>\n<p>\u201cThey had gotten into the arteries to the heart so they could choke things off,\u201d Hornbuckle said.<\/p>\n<p><strong>Related:<\/strong> <a href=\"https:\/\/www.insurancejournal.com\/news\/national\/2023\/09\/15\/740554.htm\" target=\"_blank\" rel=\"noopener\">Group in Casino Hacks Skilled at Duping Workers for Access<\/a><\/p>\n<p>Management created a war room that included executives, IT professionals, lawyers and cyber-security consultants. Employees working with guests began operating in manual mode, writing down customers\u2019 names and credit-card info on clipboards at check-in. Slot machine patrons were paid out in cash by attendants rather than via paper vouchers.<\/p>\n<p>It wasn\u2019t until days later that the hackers sent a ransom note. By that point, the attackers were knocking core systems offline, including payroll, purchasing and phones, and a booking system that handles 20,000 reservations a day.<\/p>\n<div class=\"bzn bzn-sized bzn-intext-2\">\n<ins data-revive-zoneid=\"162\" data-revive-topics=\"cyber\" data-revive-companies data-revive-block=\"1\" data-revive-id=\"36eb7c2bd3daa932a43cc2a8ffbed3a9\"><\/ins> <\/div>\n<p>\u201cLiterally everything was out,\u201d Hornbuckle said. \u201cThey clearly got wind of what we were doing and closed us down in the balance.\u201d<\/p>\n<p>Scattered Spider, a group of young men based in the US and the UK, is believed by cyber-security experts to have instigated the MGM attack, as well as a similar incursion at rival Caesars Entertainment Inc.<\/p>\n<p>After the MGM attack, Caesars confirmed it paid a ransom to hackers. Hornbuckle said he wasn\u2019t aware of the Caesars breach until after MGM was hit. He declined to disclose the amount of the ransom demand.<\/p>\n<p>The incident will reduce MGM\u2019s third-quarter earnings by about $100 million and add $10 million to expenses, most of which will be covered by insurance.<\/p>\n<p>\u201cI can only imagine what next year\u2019s bill will be,\u201d Hornbuckle said on a panel Tuesday at the Global Gaming Expo, a trade show in Las Vegas.<\/p>\n<p>Four weeks in, the casino giant\u2019s systems are fully operational, apart from one server relating to loyalty points, Hornbuckle said. He\u2019s also glad he made the decision not to pay.<\/p>\n<p>\u201cThey\u2019re not hanging over us with our database in their hand or ultimately the keys to the empire,\u201d he said. \u201cAnd so we feel great about that part.\u201d<\/p>\n<p>Photo: <em>Photographer: Roger Kisby\/Bloomberg<\/em><\/p>\n<div class=\"copyright-notice quiet\">Copyright 2023 Bloomberg.<\/div>\n<p class=\"tagtag\"> <span class=\"tagtag\">Topics<\/span> <a href=\"https:\/\/www.insurancejournal.com\/cyber\/\" class=\"btn btn-sm btn-primary tagtag\">Cyber<\/a> <\/p>\n<\/p><\/div>\n<div class=\"article-poll\" data-post=\"744088\">\n<div class=\"article-poll-vote\">\n<p>Was this article valuable?<\/p>\n<\/p><\/div>\n<div class=\"article-poll-feedback voted-no\">\n<form class=\"feedback-form\">\n<p>Thank you! Please tell us what we can do to improve this article.<\/p>\n<p> <textarea placeholder=\"Enter your feedback...\"><\/textarea> <button type=\"submit\" class=\"submit\" disabled>Submit<\/button> <button class=\"cancel\">No Thanks<\/button> <\/form>\n<\/p><\/div>\n<div class=\"article-poll-feedback voted-yes\">\n<form class=\"feedback-form\">\n<p>Thank you! <span class=\"percent\"><\/span>% of people found this article valuable. Please tell us what you liked about it.<\/p>\n<p> <textarea placeholder=\"Enter your feedback...\"><\/textarea> <button type=\"submit\" class=\"submit\" disabled>Submit<\/button> <button class=\"cancel\">No Thanks<\/button> <\/form>\n<\/p><\/div>\n<div class=\"article-poll-more-articles\">\n<p class=\"thank-you-text\">Here are more articles you may enjoy.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"subscribe-banner subscribe-banner-in-content-2\">\n<div class=\"content\">\n<h4>Interested in <em>Cyber<\/em>?<\/h4>\n<p>Get automatic alerts for this topic.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Article 0 Comments MGM Resorts International Chief Executive Officer Bill Hornbuckle chose not pay a ransom to hackers who broke into his casino chain\u2019s computer system because they didn\u2019t ask for money until well&#46;&#46;&#46;<\/p>\n","protected":false},"author":1,"featured_media":20835,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[],"tags":[325,326,327,2,1,328],"jetpack_featured_media_url":"https:\/\/blog.lifeinsurance-orleans.ca\/wp-content\/uploads\/2023\/10\/mgm-hackers-waited-for-days-before-issuing-their-ransom-demands.jpg","_links":{"self":[{"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/posts\/20834"}],"collection":[{"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/comments?post=20834"}],"version-history":[{"count":0,"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/posts\/20834\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/media\/20835"}],"wp:attachment":[{"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/media?parent=20834"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/categories?post=20834"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/tags?post=20834"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}