A look around MGM's Vegas properties, where a September 10 cyberattack has led to broken slot machines and payment kiosks, strained employees, and long waits
food ordering fucked — 1/3 slot machines dead — staff running with fanny packs to provide winnings — strip club offering perks to those impacted … Jason Koebler / @jasonkoebler@mastodon.social : I went to Vegas to enjoy the new ransomware exhibit: — https://www.404media.co/... @404mediaco@mastodon.social : We flew to Vegas to gamble at MGM's Interactive Ransomware Museum: https://www.404media.co/... What we learned: — workers have to write down every transaction with pen and paper — roughly 1/3 of slot machines are down — the Aria's billboard has become softwaregore … X: Timothy Burke / @bubbaprog : what will Danny Ocean think of next
Context & Ripple Effects
MGM first described a September 10 cybersecurity issue affecting systems across its properties, and subsequent coverage documented a website outage lasting more than 60 hours. This on-the-ground account shows how that disruption reached the casino floor and hotel operations.
The incident unfolded alongside a separate Caesars breach tied to social engineering at an outsourced IT support vendor, underscoring how cyber incidents can immediately become customer-service and revenue-operations problems for resort operators.
First-order effects
- MGM guests face unavailable slot machines and payment kiosks, disrupted food ordering, and longer waits as staff manually record transactions and distribute winnings.
- Employees absorb the operational burden of degraded systems, while Aria's public display errors make the outage visible to guests.
Second-order effects
- MGM's reduced ability to process play, payments, and orders shifts spending opportunities toward nearby venues; a local strip club is already marketing perks to affected customers.
- The Caesars incident raises pressure on casino operators and their IT vendors to review identity-verification and support-access controls, not just customer-facing uptime.
Third-order effects
- The episode illustrates the concentration risk in highly digitized hospitality operations: when central systems fail, physical venues can lose both transaction capacity and service quality at once.
- If similar incidents persist, resorts are likely to treat manual fallbacks and third-party access governance as core operational resilience requirements rather than solely IT-security concerns.
The trend: Ransomware and social-engineering attacks are turning cyber resilience into a frontline operating capability for businesses whose physical service delivery depends on centralized digital systems.