MGM Resorts' website is still down over 60 hours after being hit by a cyberattack; ransomware-as-a-service group ALPHV, aka BlackCat, reportedly took credit
1. Look up who works at a org on LinkedIn — 2. Call Help Desk (spoof phone number of person I'm impersonating) — 3. Tell Help Desk I lost access to work account & help me get back in … Kevin Beaumont / @GossiTheDog@cyberplace.social : Re #MGM - all their physical and virtual servers appear to still be offline. I've spotted their physical appliances (eg Aruba boxes, PAN etc) are online. — It wouldn't surprise me if somebody lapsus style wiped them. @da_667@infosec.exchange : Hay kids, do you like cyber violence? wanna see me stick cissp study guides under my eyelids? Watch ransomware fuck up MGM even though they just skids? — This firewall is dead weight, getting these static routes straight, meanwhile APTs got they choice of which networks to penetrate Zack Whittaker / @zackwhittaker@mastodon.social : Bloomberg is reporting that the same hackers who took down MGM Resorts this week recently targeted Caesars Entertainment, which paid millions in ransom to stop the publishing of its sensitive information. — The hacking group behind the attacks is believed to be Scattered Spider, aka 0ktapus, comprised mostly of young adults. … @hn50@social.lansky.name : Hackers claim it only took a 10-minute phone call to shut down MGM Resorts — Link: https://www.engadget.com/...
Context & Ripple Effects
The prolonged MGM outage was an early visible sign of a wider operational incident, not merely a website problem. Subsequent reporting described disrupted slot machines and payment kiosks at MGM properties, showing how a compromise can spill from corporate access into customer-facing systems.
The reported help-desk impersonation path also connected MGM to a broader cluster: Caesars later confirmed a social-engineering breach involving an outsourced IT support vendor, while Okta said MGM and Caesars were among companies targeted through help-desk calls.
First-order effects
- MGM’s public web presence remained unavailable for more than 60 hours, extending uncertainty for customers and creating a visible continuity failure for the operator.
- ALPHV’s reported claim put ransomware and identity-based help-desk compromise at the center of incident response, though a public claim alone does not establish attribution.
Second-order effects
- Other hospitality operators and their IT vendors face pressure to tighten help-desk identity verification, particularly where public professional-profile information can support impersonation.
- The Caesars incident made this a sector-level issue rather than an isolated MGM outage, increasing scrutiny of outsourced support access and recovery readiness.
Third-order effects
- If this pattern persists, resilience planning will shift from protecting endpoints alone toward treating identity recovery and support-desk workflows as critical operational controls.
- The episode points to a growing public-data permission-boundary problem: information intended for professional networking can be combined with social engineering to target enterprise access processes.
The trend: High-impact cyber incidents are increasingly exploiting human identity and support workflows to disrupt businesses whose digital systems directly run physical customer operations.