/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

MGM Resorts' website is still down over 60 hours after being hit by a cyberattack; ransomware-as-a-service group ALPHV, aka BlackCat, reportedly took credit

1. Look up who works at a org on LinkedIn  —  2. Call Help Desk (spoof phone number of person I'm impersonating)  —  3. Tell Help Desk I lost access to work account & help me get back in … Kevin Beaumont / @GossiTheDog@cyberplace.social : Re #MGM - all their physical and virtual servers appear to still be offline.  I've spotted their physical appliances (eg Aruba boxes, PAN etc) are online.  —  It wouldn't surprise me if somebody lapsus style wiped them. @da_667@infosec.exchange : Hay kids, do you like cyber violence? wanna see me stick cissp study guides under my eyelids?  Watch ransomware fuck up MGM even though they just skids?  —  This firewall is dead weight, getting these static routes straight, meanwhile APTs got they choice of which networks to penetrate Zack Whittaker / @zackwhittaker@mastodon.social : Bloomberg is reporting that the same hackers who took down MGM Resorts this week recently targeted Caesars Entertainment, which paid millions in ransom to stop the publishing of its sensitive information.  —  The hacking group behind the attacks is believed to be Scattered Spider, aka 0ktapus, comprised mostly of young adults. … @hn50@social.lansky.name : Hackers claim it only took a 10-minute phone call to shut down MGM Resorts  —  Link: https://www.engadget.com/...

Forbes Suzanne Rowan Kelleher

Context & Ripple Effects

The prolonged MGM outage was an early visible sign of a wider operational incident, not merely a website problem. Subsequent reporting described disrupted slot machines and payment kiosks at MGM properties, showing how a compromise can spill from corporate access into customer-facing systems.

The reported help-desk impersonation path also connected MGM to a broader cluster: Caesars later confirmed a social-engineering breach involving an outsourced IT support vendor, while Okta said MGM and Caesars were among companies targeted through help-desk calls.

First-order effects

  • MGM’s public web presence remained unavailable for more than 60 hours, extending uncertainty for customers and creating a visible continuity failure for the operator.
  • ALPHV’s reported claim put ransomware and identity-based help-desk compromise at the center of incident response, though a public claim alone does not establish attribution.

Second-order effects

  • Other hospitality operators and their IT vendors face pressure to tighten help-desk identity verification, particularly where public professional-profile information can support impersonation.
  • The Caesars incident made this a sector-level issue rather than an isolated MGM outage, increasing scrutiny of outsourced support access and recovery readiness.

Third-order effects

  • If this pattern persists, resilience planning will shift from protecting endpoints alone toward treating identity recovery and support-desk workflows as critical operational controls.
  • The episode points to a growing public-data permission-boundary problem: information intended for professional networking can be combined with social engineering to target enterprise access processes.

The trend: High-impact cyber incidents are increasingly exploiting human identity and support workflows to disrupt businesses whose digital systems directly run physical customer operations.

Discussion

  • @zackwhittaker@mastodon.social Zack Whittaker on mastodon
    Bloomberg is reporting that the same hackers who took down MGM Resorts this week recently targeted Caesars Entertainment, which paid millions in ransom to stop the publishing of its sensitive information.  —  The hacking group behind the attacks is believed to be Scattered Spider…
  • @vxunderground @vxunderground on x
    All ALPHV ransomware group did to compromise MGM Resorts was hop on LinkedIn, find an employee, then call the Help Desk. A company valued at $33,900,000,000 was defeated by a 10-minute conversation.
  • @_sn0ww Snow on x
    Chances are, if you stopped in the @sec_defcon this year at @defcon, you heard first hand how successful #vishing can be. 🧵
  • @vxunderground @vxunderground on x
    @let_svn No, this isn't an attempt to screw anyone over. This particular subgroup of ALPHV ransomware has established a reputation of being remarkably gifted at social engineering for initial access. It isn't really a surprise ALPHV (or the subgroup) is behind this attack.
  • @racheltobac Rachel Tobac on x
    One of the easiest ways for me to hack is simply: 1. Look up who works at a org on LinkedIn 2. Call Help Desk (spoof phone number of person I'm impersonating) 3. Tell Help Desk I lost access to work account & help me get back in I hope we learn more & get confirmation of methods
  • @vxunderground @vxunderground on x
    @arborbytes The Threat Actors themselves
  • @vxunderground @vxunderground on x
    Very cool. Thank you @Bitdefender and @TrustedSec for the kind words when speaking with @Forbes. However, we would like to note vx-underground is a collective of several people - it is not a single person. (TrustedSec knows this, maybe Mr. Hammerstone made an oopsie doopsie) [ima…