A look at the MGM hack, carried out by Star Fraud group, part of the Com online community of teenagers from English-speaking countries that also spawned Lapsus$
A gang of young criminals. A more than $30 million ransom. Casinos in disarray. Six days inside the cyberattack that put corporate America on notice.
Context & Ripple Effects
The MGM incident was already visible as an extended operational outage, with coverage reporting that the company’s website remained unavailable for more than 60 hours during the attack the prolonged MGM outage. This account adds attribution and a closer view of the criminal network behind the disruption.
The case also unfolded alongside a social-engineering breach at Caesars that reportedly involved an outsourced IT-support vendor and a ransom payment the Caesars support-vendor breach. Together, the incidents put casino operators’ identity and help-desk defenses under unusual scrutiny.
First-order effects
- MGM absorbs the immediate operational and recovery burden from a six-day disruption, while the attackers use the threat of continued disorder to press a demand exceeding $30 million.
- Star Fraud gains visibility as the group tied to the MGM intrusion, linking the attack to the broader Com community described in the reporting.
Second-order effects
- Casino operators and their IT vendors face pressure to tighten help-desk verification, privileged-access controls, and incident-response procedures after MGM and Caesars were both hit through socially mediated intrusion paths.
- Ransom demands become part of a broader business-continuity calculation for hospitality companies: the cost of disrupted reservations, gaming, and customer-facing systems can shape how urgently firms contain an attack.
Third-order effects
- If similar incidents persist, cyber resilience in hospitality will increasingly hinge on identity controls and third-party support governance rather than perimeter security alone.
- The pattern points to a more decentralized cybercrime pipeline in which online communities can produce groups capable of causing outsized disruption to large, operationally complex companies.
The trend: High-impact ransomware and extortion campaigns are increasingly exploiting human and vendor access paths to disrupt physical-world service businesses.