Investigation: for over six months, the FBI has known the identities of 12+ hackers tied to the MGM and Caesars breaches, baffling experts at the lack of action
The U.S. Federal Bureau of Investigation (FBI) has struggled to stop a hyper-aggressive cybercrime gang that's … X: @ericgeller . Forums: r/cybersecurity X: Eric Geller / @ericgeller : Reuters reports that the FBI has struggled to disrupt the “Scattered Spider” hacker gang responsible for breaching many companies (but most famously MGM and Caesars), in part b/c victims refuse to cooperate and in part b/c of poor internal coordination. https://www.reuters.com/... [image] Forums: r/cybersecurity : FBI struggled to disrupt dangerous casino hacking gang, cyber responders say
Context & Ripple Effects
The MGM and Caesars incidents had already put social engineering and third-party access at the center of the story: Caesars said its breach began through an outsourced IT-support vendor, while reporting on MGM connected the group to help-desk calls used to obtain passwords.
This report shifts the focus from attribution to disruption. The FBI’s reported knowledge of more than 12 alleged participants, alongside difficulty acting against the group, highlights the limits of identifying attackers when victim cooperation and agency coordination are uneven.
First-order effects
- The FBI faces sharper scrutiny over why known alleged members tied to the MGM and Caesars breaches were not more effectively disrupted.
- MGM, Caesars, and other victims have a stronger immediate incentive to cooperate with investigators, because victim participation is identified as a constraint on action against the group.
Second-order effects
- Organizations reliant on outsourced support and help desks will face pressure to strengthen identity-verification and escalation controls, given the reported role of social engineering in the casino breaches.
- Cybercrime groups may continue to benefit when investigations cannot readily turn attribution into coordinated disruption, raising the value of defensive controls that do not depend on a rapid law-enforcement response.
Third-order effects
- The episode points to ecosystem cyber defense becoming more operational: companies, service providers, and law enforcement may need more consistent information-sharing and response mechanisms to counter socially engineered intrusions.
- If this pattern persists, the practical gap between identifying cybercrime actors and stopping them will make resilience at customer-support and vendor access points a more durable competitive and regulatory concern.
The trend: High-profile social-engineering incidents are pushing cyber defense toward coordinated ecosystem controls rather than reliance on attribution or post-breach enforcement alone.