Turns out the house doesn’t always win in Las Vegas — sometimes the hackers do.
Caesar’s Entertainment and MGM Resorts have each been targeted by a Russian hacking group known as Scattered Spider.
Caesars paid the group tens of millions to the group after its members breached an outside IT vendor, gained access to the company’s network and threatened to release its data, according to reports. Caesars stock gained 1% Thursday morning to $52.87 but is down 3.8% overall this week.
Meanwhile, MGM Resorts International (NSX:MGM) disclosed a “cybersecurity issue” in a regulatory filing earlier this week. Shares of MGM are up 0.9% to $41.83 but down about 4% this week.
The casino hotel claims to have the issue under control, but social media posts suggest that all sorts of electronic-based services (like room keys, food cards and certain slot machines) have been shot down.
Instead, MGM is reportedly being forced to go analog with manual cash payouts and physical room keys.
Scattered Spider is notorious for using what’s called social engineering to uncover login credentials or one-time passcodes that allow them to skip past multi-factor authentication.
In the case of MGM, all the group needed was a quick phone call and some help from a ransomware-as-a-service group called ALPHV, also known as BlackCat, according to the malware research group VX-Underground.
All ALPHV ransomware group did to compromise MGM Resorts was hop on LinkedIn, find an employee, then call the Help Desk.
A company valued at $33,900,000,000 was defeated by a 10-minute conversation.
— vx-underground (@vxunderground) September 13, 2023
It’s also no surprise that Las Vegas casinos have been Scattered Spider’s targets, according to Allan Liska, an intelligence analyst at the security firm Recorded Future.
Casino cybersecurity often isn’t the top of the line and hackers are “more likely to get paid because they’re disrupting casino operations,” Liska said in an interview with Reuters. “Casinos around the world should be on heightened alert because ransomware groups love it when they get this kind of attention, so we will likely see copycats.”
Analysts unfazed
Despite the impacts on consumers, analysts at Jefferies don’t see the hacks as bad news for the company’s stock
“The announcement by CZR and indications from MGM confirming the cyberattacks should be taken as one-time, largely insurable events that should not have long-lasting impacts on the businesses, assuming that the event is short-lived,” the analysts wrote.
“Our sense is that MGM's impact could potentially be material but moderate near term, while CZR should see no meaningful impact and the question of whether any business is displaced among operators near term is fair.”
The firm has a $70 price target for Caesars and a $69 target for MGM, with Buy ratings for both.
“Our impression of the impact to MGM is that business remains operable and credit card use is possible, albeit manual, while more transactions are cash-based than usual,” the analysts added. “We would expect, however, that group and transient business in the near term could be impacted by ~10%-20% for the days that the current conditions exist.”
“Again, we expect this impact is one-time and insurable, so would have little impact on value over time.”
Contact Andrew Kessel at andrew.kessel@proactiveinvestors.com
Follow him on Twitter @andrew_kessel