MGM Resorts got hacked (Read 1764 times)

changemyoil66

MGM Resorts got hacked
« on: September 22, 2023, 01:36:19 PM »
His happened about 2 weeks ago.  This is not just the MGM Hotel in Vegas, but the entire MGM Resorts company. So Bellagio, NYNY, Mirage, Aria, Excalubur, etc...Not sure if Cosmo was affected as they had their own Identity company, but was sold to MGM recently.

But what I find interesting is it's been 2 weeks and not a peep on our local news, even though Vegas is the 9th Island.  Since we go to Vegas so often, I have alternate information sources for NV/Vegas updates.

MGM properties, at first all slots were out of order, all check ins and check outs had to be done manually. Room keys didnt work (RFID/FOB type), their website was down, their app was down, credit card machines in stores and restaurants didn't work, ATM"s all down, etc..Some even had their elevators and AC's not work correctly.  Then very slowly stuff is coming back, but not at normal like how the MGM stated on their Twitter. OPERATIONS ARE NOT BACK TO NORMAL.

Employee payroll was maintained, but some were short hours.  Employees cannot log into the employee website to check their work schedules, PTO available, 401K balance, and their socials, birthdays and those who they had on the system like spouses and childrens socials and birthdays have been compromised.

About a week after this, some slots were working, but no one could cash out via a cash out ticket. They had to wait for a handpay.  So you put in $100 and lose $50 and want to switch to another machine. You had to wait about an hour until a slot attendant came by and gave you your money back from the machine.  Check in times at the Excalibur were like up to 7 hours and their line was out the door. 

Today, more slots are working, but instead of some saying "out of order", it just wont accept any money. Guess MGM thought this was a good idea to give the image that they're back to normal.  Hand payments have been reduced to about 15 mins, but you still cannot cashout tickets in certain machines/locations.  TBH, I wouldn't play a slot machine because any big win might be voided due to the hack excuse the casino might use.

Vegas media reported more of this, but it's people posting vids of what's not working is where most of the information comes from and from the workers.

This happened to the Ceasars company in July and they paid off the hackers like $15 million to restore everything. This wasn't just the Ceasars Hotel, but the company. So Harrahs Hotel, Planet Hollywood, etc...

It doesn't look like MGM will pay off tfhe hackers.

Other hotels outside of the MGM system are fine so far. 

Flapp_Jackson

Re: MGM Resorts got hacked
« Reply #1 on: September 22, 2023, 04:31:42 PM »
Yeah, this Ramsomware attacks on big companies highlight the total lack of seriousness they possess when funding for IT.

When an organization runs for years and years with no major downtime and no successful hacks, they start to become complacent about how much those high-priced IT professionals are costing them.  It becomes a situation of "They keep the problems from happening," while management wonders, "If we aren't having problems, why are we paying these people?"

Most of my time when dealing with live systems was spent hardening the network and servers to prevent, detect and recover from intrusions and failures.  The better I did my job, the less anyone ever heard about what i was doing.

Over time, the managers start paying for maintenance contracts offered by vendors, because a few grand a year is way cheaper than the salaries and other costs of having an IT staff on the payroll.

Until this kind of stuff happens.  They are losing more money now than their reduced in-house expertise could ever save them.

No computer is unhackable.  Therefore, you have to have a backup and recovery plan that accounts for these attacks as well as a dozen other potential causes.  How long can you afford for your systems to be down?  That's how long it should take to recover the systems -- or less.

Sometimes it's just a hardware failure, but the objective is the same:  do you keep a hot spare online?  do you have a cold spare in a box ready to restore a backup on and bring online?  do you have cloud backups in case a fire destroys local backups?  how far back do the backups go?

So many things to consider when devising a backup and recovery plan.   Maybe i should see if MGM is hiring IT folks now ...   :geekdanc:
The reasonable man adapts himself to the world;
the unreasonable one persists in trying to adapt the world to himself.
Therefore, all progress depends on the unreasonable man.
-- George Bernard Shaw

changemyoil66

Re: MGM Resorts got hacked
« Reply #2 on: September 22, 2023, 06:34:17 PM »
Yeah, this Ramsomware attacks on big companies highlight the total lack of seriousness they possess when funding for IT.

When an organization runs for years and years with no major downtime and no successful hacks, they start to become complacent about how much those high-priced IT professionals are costing them.  It becomes a situation of "They keep the problems from happening," while management wonders, "If we aren't having problems, why are we paying these people?"

Most of my time when dealing with live systems was spent hardening the network and servers to prevent, detect and recover from intrusions and failures.  The better I did my job, the less anyone ever heard about what i was doing.

Over time, the managers start paying for maintenance contracts offered by vendors, because a few grand a year is way cheaper than the salaries and other costs of having an IT staff on the payroll.

Until this kind of stuff happens.  They are losing more money now than their reduced in-house expertise could ever save them.

No computer is unhackable.  Therefore, you have to have a backup and recovery plan that accounts for these attacks as well as a dozen other potential causes.  How long can you afford for your systems to be down?  That's how long it should take to recover the systems -- or less.

Sometimes it's just a hardware failure, but the objective is the same:  do you keep a hot spare online?  do you have a cold spare in a box ready to restore a backup on and bring online?  do you have cloud backups in case a fire destroys local backups?  how far back do the backups go?

So many things to consider when devising a backup and recovery plan.   Maybe i should see if MGM is hiring IT folks now ...   :geekdanc:
They are as 1099 (contactor). $100hr, must work 10hrs a day and 7 days a week.

Ill bet theres a clause in their contract that they are gonna withhold pay until a certain level of completion is accomplished.


Sent from my SM-G991U using Tapatalk

Sodie

Re: MGM Resorts got hacked
« Reply #3 on: September 22, 2023, 06:41:10 PM »
Yeah, this Ramsomware attacks on big companies highlight the total lack of seriousness they possess when funding for IT.

When an organization runs for years and years with no major downtime and no successful hacks, they start to become complacent about how much those high-priced IT professionals are costing them.  It becomes a situation of "They keep the problems from happening," while management wonders, "If we aren't having problems, why are we paying these people?"

Most of my time when dealing with live systems was spent hardening the network and servers to prevent, detect and recover from intrusions and failures.  The better I did my job, the less anyone ever heard about what i was doing.

Over time, the managers start paying for maintenance contracts offered by vendors, because a few grand a year is way cheaper than the salaries and other costs of having an IT staff on the payroll.

Until this kind of stuff happens.  They are losing more money now than their reduced in-house expertise could ever save them.

No computer is unhackable.  Therefore, you have to have a backup and recovery plan that accounts for these attacks as well as a dozen other potential causes.  How long can you afford for your systems to be down?  That's how long it should take to recover the systems -- or less.

Sometimes it's just a hardware failure, but the objective is the same:  do you keep a hot spare online?  do you have a cold spare in a box ready to restore a backup on and bring online?  do you have cloud backups in case a fire destroys local backups?  how far back do the backups go?

So many things to consider when devising a backup and recovery plan.   Maybe i should see if MGM is hiring IT folks now ...   :geekdanc:

Yep, that’s the thing about fields like IT/cybersecurity.  How do you know it’s working? Because nothing happens.  That can be a tough sell.

changemyoil66

Re: MGM Resorts got hacked
« Reply #4 on: September 26, 2023, 07:59:28 AM »
They think the hacking group got in from getting info from an IT"s Linkin profile, then using that to call help desk and saying they cannot get into their log on account.

oldfart

Re: MGM Resorts got hacked
« Reply #5 on: September 26, 2023, 08:47:45 AM »
I saw a story about KITV.
They were unable to put on their news for a few days.
I wouldn't be surprised if their computers got hacked.
Everything is computers nowadays.
What, Me Worry?

QUIETShooter

Re: MGM Resorts got hacked
« Reply #6 on: September 26, 2023, 09:05:22 AM »
New World Order

Government controlled spending accounts

Artificial Intelligence

Society's almost 100% dependence on mobile devices

Whoo Hoo. Future doesn't look that great to me.  I'm a pencil and paper guy.  Gives me a sense of freedom and being my own person.

This other paperless crap gives me the feeling like Big Brother is always looking over my shoulder.

Fact is:  He is.
Sometimes you gotta know when to save your bullets.