Source: MGM Resorts refused to pay a hackers' ransom in the September cyberattack; filing: MGM estimates the hack will cost the company $100M+ in its Q3 2023
Fallout will have a $100 million negative impact on quarterly earnings, Las Vegas-based company says
Context & Ripple Effects
MGM had already disclosed that a cybersecurity issue was affecting systems across its U.S. casino and hotel properties, making the estimated quarterly impact a measure of the operational fallout from the initial systems disruption.
The episode unfolded alongside a nearby industry contrast: Caesars reportedly paid after its breach and later confirmed a social-engineering attack involving an outsourced IT support vendor. MGM’s refusal puts the cost of disruption, rather than just the ransom decision, at the center of the comparison.
First-order effects
- MGM absorbs an estimated more-than-$100 million hit to Q3 earnings after refusing the attackers’ ransom demand.
- The filing turns a systems outage at MGM properties into a disclosed financial consequence for the operator and its investors.
Second-order effects
- The differing MGM and Caesars outcomes give other casino operators a concrete comparison between ransom exposure and the potentially larger business cost of prolonged disruption.
- Cybersecurity planning at hospitality operators is likely to focus more tightly on restoring customer-facing and property systems, since outage costs can rapidly become material even without a ransom payment.
Third-order effects
- If similar incidents continue, ransomware will be treated less as a contained IT event and more as an operational-resilience risk with direct earnings, disclosure, and liability consequences; later coverage of MGM’s $45 million breach-related settlement shows that costs can extend beyond the initial outage.
The trend: High-disruption cyberattacks are pushing service-heavy businesses to price cyber risk around operational continuity and downstream liability, not only stolen data or ransom demands.