In September 2023, MGM Resorts International and Caesars Entertainment, two of the largest casino and hotel operators in Las Vegas, were hit within days of each other by the same cybercriminal group. The attacks knocked out slot machines, digital room keys, and reservation systems at MGM for over a week. They forced Caesars to pay a multimillion-dollar ransom to keep stolen customer data from being leaked.
The Attack
Neither company was breached through a software exploit. According to a joint Cybersecurity Advisory from the FBI and the Cybersecurity and Infrastructure Security Agency (CISA), the attackers relied almost entirely on social engineering: phone calls to IT help desks, SIM-swapping to intercept one-time passcodes, and repeated multi-factor authentication prompts sent until an employee approved one by mistake, a tactic known as push bombing.
Caesars disclosed in a filing with the US Securities and Exchange Commission that attackers gained access through a social engineering attack on a third-party IT support vendor. MGM's own SEC filing described a similar pattern: an attacker posing as an employee whose name and details had been pulled from LinkedIn, convincing the company's help desk to reset a password. From there, the attackers stole customer data and, in MGM's case, deployed ransomware against the company's VMware ESXi servers, disrupting operations across its Las Vegas properties for days.
Caesars' SEC filing confirmed a ransom had been paid to prevent the release of stolen data, without stating an amount. The Wall Street Journal reported the figure at roughly $ 15 million, about half of the attackers' original $ 30 million demand. MGM did not pay, according to CNBC reporting citing sources familiar with the incident, and absorbed the operational damage instead.
Who's Behind It
The FBI and CISA advisory identifies the group behind these attacks as Scattered Spider, also tracked under the aliases UNC3944, Octo Tempest, Muddled Libra, and 0ktapus. Google's Mandiant threat intelligence team, which uses the UNC3944 designation, has documented the group's tactics since 2022, describing a shift from SIM-swapping fraud toward ransomware and large-scale data extortion by early 2023.
According to US prosecutors, the specific individuals who carried out the MGM and Caesars intrusions referred to their operation as Star Fraud, one cell within a larger, loosely organized network of English-speaking hackers known online as the Com. The ransomware deployed against MGM was ALPHV, also called BlackCat, a ransomware-as-a-service operation that its own operators have acknowledged grew out of the earlier BlackMatter and DarkSide groups, the same lineage responsible for the 2021 Colonial Pipeline attack.
The Fallout
MGM's disruption lasted roughly nine days and affected everything from digital key cards to slot machines and online reservations. In 2025, MGM reached a 45 million dollar settlement resolving consolidated class-action lawsuits over the 2023 breach along with a separate 2019 incident, covering an estimated 37 million affected customers, according to a preliminary approval order from the US District Court for the District of Nevada.
Caesars avoided a comparable operational outage by paying the ransom, though its own SEC filing acknowledged it could not guarantee the attackers would actually delete the stolen data as promised.
Where It Stands Now
Law enforcement action against the group has continued for years after the initial breach. The US Department of Justice has unsealed multiple indictments against alleged Scattered Spider members, including a 2024 case naming five defendants on charges tied to phishing campaigns and cryptocurrency theft. In 2025, a British national identified by prosecutors as a central figure in the group, Thalha Jubair, was arrested and later sentenced in the UK for a separate hack against Transport for London, while separately facing US charges connected to the broader Scattered Spider campaign.
CISA and the FBI, joined by law enforcement partners in Canada, Australia, and the UK, have continued to update their joint advisory on the group as recently as mid-2025, noting a shift toward new ransomware variants and continued targeting of IT help desks across industries well beyond hospitality.
Sources
Cybersecurity and Infrastructure Security Agency and Federal Bureau of Investigation, joint Cybersecurity Advisory AA23-320A, "Scattered Spider," co-authored with the Royal Canadian Mounted Police, Australian Federal Police, Australian Cyber Security Center, Canadian Center for Cyber Security, and UK National Cyber Security Center. cisa.gov/news-events/cybersecurity-advisories/aa23-320a
US Department of Justice, Office of Public Affairs, "Alleged Member of Criminal Cyber Hacking Group 'Scattered Spider' Arrested in Finland and Extradited to the United States." justice.gov/opa/pr/alleged-member-criminal-cyber-hacking-group-scattered-spider-arrested-finland-and-extradited
Google Cloud Blog, Mandiant, "Why Are You Texting Me? UNC3944 Leverages SMS Phishing Campaigns for SIM Swapping, Ransomware, Extortion, and Notoriety." cloud.google.com/blog/topics/threat-intelligence/unc3944-sms-phishing-sim-swapping-ransomware
Google Cloud Blog, Mandiant, "Defending Against UNC3944: Cybercrime Hardening Guidance from the Frontlines." cloud.google.com/blog/topics/threat-intelligence/unc3944-proactive-hardening-recommendations
MGM Resorts International, Form 8-K, US Securities and Exchange Commission, September 2023.
Caesars Entertainment, Form 8-K, US Securities and Exchange Commission, September 2023.
US District Court for the District of Nevada, order granting preliminary approval of class-action settlement, MGM data breach litigation, January 2025.
Casino.org, "UK Jails Alleged Scattered Spider Leader Linked to MGM Resorts and Caesars Cyberattacks," reporting on US prosecutors' allegations regarding the Star Fraud designation. casino.org/news/uk-jails-alleged-scattered-spider-leader-linked-to-mgm-resorts-and-caesars-cyberattacks
CNBC, "Caesars paid millions in ransom to cybercrime group before MGM hack," reporting on the ransom figures and MGM's decision not to pay. cnbc.com/2023/09/14/caesars-paid-millions-in-ransom-to-cybercrime-group-prior-to-mgm-hack.html