/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Source: MGM Resorts refused to pay a hackers' ransom in the September cyberattack; filing: MGM estimates the hack will cost the company $100M+ in its Q3 2023

Fallout will have a $100 million negative impact on quarterly earnings, Las Vegas-based company says

Wall Street Journal Katherine Sayre

Context & Ripple Effects

MGM had already disclosed that a cybersecurity issue was affecting systems across its U.S. casino and hotel properties, making the estimated quarterly impact a measure of the operational fallout from the initial systems disruption.

The episode unfolded alongside a nearby industry contrast: Caesars reportedly paid after its breach and later confirmed a social-engineering attack involving an outsourced IT support vendor. MGM’s refusal puts the cost of disruption, rather than just the ransom decision, at the center of the comparison.

First-order effects

  • MGM absorbs an estimated more-than-$100 million hit to Q3 earnings after refusing the attackers’ ransom demand.
  • The filing turns a systems outage at MGM properties into a disclosed financial consequence for the operator and its investors.

Second-order effects

  • The differing MGM and Caesars outcomes give other casino operators a concrete comparison between ransom exposure and the potentially larger business cost of prolonged disruption.
  • Cybersecurity planning at hospitality operators is likely to focus more tightly on restoring customer-facing and property systems, since outage costs can rapidly become material even without a ransom payment.

Third-order effects

  • If similar incidents continue, ransomware will be treated less as a contained IT event and more as an operational-resilience risk with direct earnings, disclosure, and liability consequences; later coverage of MGM’s $45 million breach-related settlement shows that costs can extend beyond the initial outage.

The trend: High-disruption cyberattacks are pushing service-heavy businesses to price cyber risk around operational continuity and downstream liability, not only stolen data or ransom demands.

Discussion

  • @davidsvendsen David Svendsen on x
    MGM refused to pay the ransom. Good! Don't ever pay these. It only emboldens those groups to keep doing it. Instead: - Fix/re-build (no matter the cost) - Recoup what you can from insurance - Come up with a better DR plan - Stop underfunding IT https://www.wsj.com/...
  • @jg_report Jay Gershbein on x
    (4.4) #MGM's decision not to pay hackers is in line with guidance from the #FBI, which doesn't support paying ransom. Doing so doesn't guarantee that a company will recover its data, but rewards hackers to target more victims, the FBI's website says. https://www.wsj.com/... @WSJ …
  • @sharkbiotech Dan Rosenblum on x
    so $MGM decision not to pay hackers ransom of $50 million or whatever cost them $3.5 billion in market cap I understand their refusal to give in to hackers but not sure its the right thing to do by shareholders
  • r/technews r on reddit
    MGM Resorts confirms hackers stole customers' personal data during cyberattack