MGM Resorts Breach 2023: Business Continuity and Operational Resilience
Updated: Aug 31
Part one told how a ten-minute phone call breached MGM. This is what the next ten days cost: dark slot floors, handwritten check-ins, a refusal to pay, and a $100 million lesson in what operational resilience actually means.
Case type: Ransomware / operational disruption
Identified: Sept 10, 2023 Disclosed: Sept 11, 2023
Attribution: Scattered Spider / ALPHV
Part one of this case examined how a ten-minute phone call gave attackers the keys to MGM Resorts. This companion piece examines what happened next, because the breach that made headlines wasn't really about stolen data. It was about ten days when one of the world's largest hospitality companies had to operate by hand.
Prevention failed in minutes. What followed was a live, involuntary test of business continuity, run in public, across casino floors and hotel lobbies, with the bill eventually itemized in a securities filing. This post reads the MGM incident as that test: the shutdown decision, the manual days, the economics of refusing to pay, and what any organization can take from a company that chose the hard road and could afford to.
The entry is part one's story in brief: attackers researched an employee on LinkedIn, called MGM's help desk impersonating them, and talked their way into privileged access in roughly ten minutes. What matters here is what MGM did on September 10, when it detected the intrusion: it began shutting down its own systems, including pieces of its identity infrastructure, to cut the attackers off. Much of the outage the public attributed to hackers was, in the strictest sense, self-inflicted, and deliberately so. It was containment, priced in downtime.
The attackers answered on September 11 by detonating ALPHV ransomware across more than 100 ESXi hypervisors, the virtualization layer beneath large swaths of MGM's environment. Between the encryption and the defensive shutdowns, the disruption became total and visible: digital room keys died, so staff escorted guests with physical keys. Check-in went to pen and paper. Sections of slot floors went dark, and winnings were paid in cash against handwritten receipts. The website and app went down, pushing reservations to phone lines. It stayed that way, in varying degrees, for roughly ten days, while MGM, advised by outside firms and in contact with the FBI, declined to pay. On September 20, the company announced its hotels and casinos were operating normally.
The costs arrived with unusual clarity. In an October 5 SEC filing, MGM put the negative impact at roughly $100 million of quarterly property earnings, concentrated in its Las Vegas operations, essentially lost revenue from the disrupted days, plus under $10 million in one-time response costs, and stated it expected cyber insurance to substantially cover the impact. That precision is rare, and it is why this incident became the reference case for the economics of refusing to pay, especially standing next to its twin: Caesars, breached by the same crews three weeks earlier, paid roughly $15 million and never went dark. Part one of this series covers that contrast from the attack side; this post covers it from the ledger.
The ransom was never the biggest number
Most ransomware coverage fixates on the demand. MGM's case shows why that's the wrong number to watch. The demand was never disclosed; the operational cost was: $100 million in lost earnings from ten days of degraded operations. For any organization running physical operations on digital rails, the real exposure isn't what attackers ask for. It's what each day of disruption costs, multiplied by how many days recovery takes. That number exists for every company, whether or not anyone has calculated it.
Resilience isn't whether the bad day comes. It's what still runs while it's happening.
MGM's refusal to pay only reads as strength because the company could absorb the consequence: deep operations, insurance coverage, and customers with nowhere better to be on the Strip. The same decision at a company with thinner margins, no coverage, and no manual fallback isn't principle. It's improvisation under duress. Which is the point: the pay-or-refuse posture is only genuinely a choice for organizations that prepared to survive their own answer.
MGM turned itself off before the attackers could
The most consequential move of the incident wasn't the attackers'. It was MGM's decision, within hours of detection, to power down its own systems and sever its identity infrastructure, accepting a self-inflicted outage to stop lateral movement. It almost certainly limited the data loss, and it converted a security incident into an operational one on MGM's terms rather than the attackers'. But it also exposed the preparation gap: the shutdown was decisive, and what followed it was improvised. A containment plan that ends at "pull the plug" is half a plan. The other half is knowing, in advance, what the business does while the plug is out.
Paper worked. Nobody had practiced it
What actually carried MGM through the outage wasn't technology. It was front-line staff improvising analog versions of digital processes in real time, in front of customers:
Guests experienced the breach not as a headline but as a queue, and employees absorbed the difference between the company's systems and its promises. That's the part continuity planning most often misses: the fallback isn't a binder, it's people, and people execute under pressure roughly as well as they've rehearsed. MGM's staff performed admirably. They also should never have been the first draft of the plan.
Not one decision. A set of conditions.
The interesting question for other organizations isn't "should MGM have paid?" It's: what conditions set the price of refusing at ten days and $100 million, and which of those conditions do we share?
Not paying cost $100 million. Paying wouldn't have cost zero.
Set the twins side by side one more time. Caesars paid roughly $15 million, kept operations running, and still got the litigation, the regulatory scrutiny, and no guarantee its data was deleted. MGM refused, absorbed a $100 million operational hit that insurance substantially covered, and still settled the consolidated class action, $45 million spanning its 2019 and 2023 incidents, roughly 37 million people combined. Neither company bought its way out of consequence. The variable that actually separated their experiences wasn't the payment decision. It was how long refusal costs, and that number is set before the attack: by architecture, by fallbacks, and by rehearsal. Organizations that can restore in two days can refuse anyone. Organizations that need two months can't afford their own principles.
"Continuity Is a Decision Made in Advance."
The MGM incident is remembered as the breach that turned off Las Vegas. It deserves to be remembered as the incident that put a public price on resilience: ten days and $100 million, disclosed to the dollar, for the choice to contain rather than capitulate. MGM could make that choice because of what it had, deep operations, insurance, loyal demand, and because of what its people improvised. What it couldn't show was preparation equal to its principles.
Every organization now gets to learn that lesson at MGM's expense instead of its own. Calculate the day-rate of your own disruption. Decide the payment question before anyone demands anything. Rehearse the paper version of your business with the people who would run it. The companies that fare best against modern extortion aren't the ones that never get breached. They're the ones for whom refusal is affordable.
BECAUSE WHEN THE SYSTEMS GO DARK, THE ONLY PLANS THAT WORK ARE THE ONES THAT EXISTED BEFORE THE LIGHTS WENT OUT.
Sources
MGM Data Breach Settlement, "MGM International Resorts Data Breach Litigation": https://mgmdatasettlement.com/
CISA, "#StopRansomware: Scattered Spider," November 16, 2023: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a
DataBreachCost.com, "MGM Resorts 2023: ~$100M from a 10-minute phone call": https://databreachcost.com/case/mgm-2023


Comments