MGM Resorts has concluded a 10-day computer shutdown, initiated on September 10, to safeguard sensitive data, including hotel reservations and credit card information.
The Las Vegas-based company announced the return to normal operations via X, stating: "We are pleased that all of our hotels and casinos are operating normally."
MGM Resorts is the largest private employer in Nevada and runs numerous hotels in Las Vegas, including those in well-known properties like MGM Grand and Bellagio.
The company also has resorts in China and Macau and employs around 75,000 people worldwide.
The attack is attributed to the Russia-based Scattered Spider hacking group, raising questions about the adequacy of cybersecurity defences in the casino industry at large.
Please read our latest update below. Learn more: https://t.co/INKgreBSrt pic.twitter.com/N4zbQEFJFr
— MGM Resorts (@MGMResortsIntl) September 20, 2023
Daily losses of $8 million
Gregory Moody, a cybersecurity expert at the University of Nevada, Las Vegas, offered estimates suggesting that MGM's daily losses could reach up to $8 million.
Lisa Plaggemier, executive director of the National Cybersecurity Alliance, commended MGM Resorts for proactively shutting down susceptible systems to thwart cyber intrusion.
However, she noted that this action underscored glaring security shortcomings and accentuated the imperative for hefty investments in cybersecurity and employee education.
She pointed out that the associated risks included operational downtime and financial repercussions.
As for MGM Resorts, specific details concerning the scope of the cyber breach remain undisclosed, including the nature of potentially compromised information and the financial toll on the company.