In September 2023, two of the largest casino and resort operators in Las Vegas were simultaneously compromised by the same loosely organized group of young, English-speaking hackers. MGM Resorts International fought back and suffered for it - slot machines went dark across its properties, hotel check-in systems failed, ATMs stopped working, and the company reported $100 million in losses from the disruption. Caesars Entertainment quietly paid a ransom estimated at $15 million and largely kept operations running. The contrast in outcomes generated enormous debate in the security industry about the ethics and pragmatics of paying ransomware operators.

The Attackers: Scattered Spider

The group responsible - called Scattered Spider by CrowdStrike, Octo Tempest by Microsoft, UNC3944 by Mandiant - was not a traditional Eastern European ransomware gang. It was a network of teenagers and young adults, primarily American and British, who communicated over Discord, Telegram, and underground forums. Most spoke English natively. They were affiliated with the broader "COM" underground that had also produced LAPSUS$, the Twitter hacker Graham Clark, and the SIM swapping scene.

Their tradecraft was not malware but conversation. They called IT help desks. They posed as employees who had lost access to their accounts. They used social security numbers and other personally identifiable information - purchased from data brokers or stolen databases - to pass identity verification. They used MFA fatigue, SIM swapping, and voice phishing. In some cases, they recruited or coerced insiders. Once inside a target's network, they used legitimate tools - living off the land - to avoid detection.

[WARNING]
The Scattered Spider attacks against MGM and Caesars used a specific social engineering technique against Okta help desks that became a definitive case study. An attacker called the MGM help desk, identified themselves as an employee (using information from LinkedIn), and requested an MFA reset. The call was sufficient - the help desk representative performed the reset. This gave the attacker access to corporate systems. The subsequent network compromise, ALPHV/BlackCat ransomware deployment, and operational shutdown of MGM properties followed from a single 10-minute phone call.

Caesars: The Quiet Payment

The Caesars attack preceded MGM's and was handled very differently. Scattered Spider accessed Caesars through a third-party IT vendor - a managed service provider that had access to Caesars' systems. Once inside, they exfiltrated data including the Caesars Rewards loyalty program database containing personal information of tens of millions of customers.

Scattered Spider demanded $30 million. Caesars negotiated to approximately $15 million and paid. The operational impact to Caesars was minimal - the ransomware was not deployed widely, and the primary leverage was the threat to release stolen data. Caesars disclosed the breach in an SEC filing in September 2023 (post-SEC breach disclosure rule) but did not publicly acknowledge the ransom payment until media reporting confirmed it.

MGM: Fighting Back and Paying the Consequences

MGM, by contrast, declined to pay. Their incident response - led by Mandiant - involved taking systems offline to contain the intrusion. The decision was defensible from a security standpoint but catastrophic from an operational one. MGM's hotels, casinos, and resorts are inseparably dependent on their IT systems: slot machines, hotel room keys, restaurant reservations, casino cage operations, and guest check-in are all networked.

For approximately 10 days, MGM properties operated in degraded or manual mode. Slot machines across Las Vegas strip properties went dark. Hotel guests could not use digital room keys. Lines formed for manual check-in. ATMs failed. Some casino cage operations reverted to paper processes. The Las Vegas convention business, which generates substantial revenue for MGM properties, was partially disrupted.

MGM disclosed a $100 million revenue impact from the disruption. The ALPHV/BlackCat ransomware group (which Scattered Spider had partnered with as an affiliate, providing access while BlackCat provided ransomware) also exfiltrated personal data on MGM customers - including driver's license numbers, Social Security numbers, and passport information - and threatened to release it.

The ALPHV/Scattered Spider Partnership

The MGM and Caesars attacks illustrated a model that had become common in the ransomware ecosystem: initial access brokers partnering with established ransomware groups. Scattered Spider provided the social engineering expertise and initial network access; ALPHV/BlackCat provided the ransomware payload and the ransom negotiation infrastructure (including a leak site for stolen data). Revenue was split.

This division of labor allowed both parties to specialize. Scattered Spider's members were skilled social engineers but not malware developers. ALPHV/BlackCat had sophisticated ransomware and infrastructure but less expertise in the initial access phase for certain types of targets. The partnership combined their respective advantages.

ALPHV/BlackCat was subsequently disrupted by the FBI and international law enforcement in December 2023 - just months after the MGM attack. The disruption involved seizing BlackCat's leak site and decryption keys. BlackCat's operators responded by lifting their affiliate restrictions and effectively closing down, in what appeared to be an exit scam that took affiliate deposits. Several of the ransomware ecosystem's most significant actors of 2022-2023 - Hive, BlackCat, LockBit - were disrupted by law enforcement within a roughly 18-month period.

[INFO]
The SEC's new breach disclosure rules, which took effect in December 2023 and require public companies to report material cybersecurity incidents within four business days, were directly informed by the pattern of delayed or minimal disclosures exemplified by the MGM and Caesars attacks (both of which were disclosed under earlier voluntary reporting frameworks that allowed more ambiguity about timing and detail). Caesars' SEC 8-K disclosure was notably sparse about what had actually occurred.

Arrests and the Age Problem

The FBI and UK's National Crime Agency identified and arrested several members of Scattered Spider in 2023 and 2024. Noah Michael Urban (22, Florida), Tyler Robert Buchanan (23, UK), Joel Martin Evans (25, North Carolina), and others were charged with conspiracy to commit wire fraud, aggravated identity theft, and other charges. The Buchanan arrest in Spain in June 2024 was notable - he was alleged to have stolen $26 million in cryptocurrency through SIM swapping.

The age and background of Scattered Spider members presented the same challenge as LAPSUS$: the criminal justice system's frameworks for sentencing were designed for adults engaging in deliberate organized crime, not for teenagers and young adults who had grown up in an online subculture where increasingly serious crimes escalated gradually from trading usernames to ransoming billion-dollar corporations. Several members faced potential sentences measured in decades under federal sentencing guidelines for financial crimes.