Casino giant MGM expects $100 million hit from hack that led to data breach


FILE PHOTO: An exterior view of MGM Grand hotel and casino, after MGM Resorts shut down some computer systems due to a cyber attack in Las Vegas, Nevada, U.S., September 13, 2023. REUTERS/Bridget Bennett/File Photo

(Reuters) -MGM Resorts International said on Thursday a cyberattack last month that disrupted its operations would cause a $100 million hit to its third-quarter results, as it works to restore its systems.

One of the world's largest gambling firms, MGM shut down its systems after detecting the attack to contain damage, it said. It expects to also incur less than $10 million as a related one-time cost in the quarter ended on Sept. 30.

After the attack last month, customers posted social media images showing slot machines with error messages and queues at hotels in Las Vegas.

A hacking group named AlphV claimed it was involved in the breach. Sources earlier told Reuters AlphV worked with another outfit named Scattered Spider to break into MGM systems and steal data to hold for extortion.

MGM has declined to comment on whether it was asked for or paid any ransom.

The private data of customers who used MGM services before March 2019, including contact information, gender, date of birth and driver’s license numbers, was breached, the company said.

"We also believe a more limited number of Social Security numbers and passport numbers were obtained," it said.

"We have no evidence that the criminal actors have used this data to commit identity theft or account fraud."

Hackers often hold stolen data for ransom and may also leak it to public forums or sell it to other cybercriminals.

The MGM data breach, which the FBI is investigating, is a vivid example of how large organizations remain vulnerable to cybercrime. Analysts who have tracked Scattered Spider say more and more organizations have been falling for the group's skilled social engineering schemes.

MGM said the hackers did not obtain any customer bank account numbers or payment card information, and that no data from its luxury resort hotel The Cosmopolitan of Las Vegas was breached.

"The full scope of the costs and related impacts of this issue has not been determined," MGM said in a regulatory filing.

The company expects the breach will have a negative impact of about $100 million to its adjusted property core profit for its Las Vegas Strip division, and expects total occupancy of 93% this October versus 94% in the same month a year ago.

"Virtually all of the Company's guest-facing systems have been restored," it said, adding that it expects no impact on its full-year results from the breach.

MGM said it is "well-positioned" to have a strong fourth quarter with record results in November, driven mainly by a Formula One racing event slated to take place in Las Vegas.

(Reporting by Zeba Siddiqui in San Francisco and Shivansh Tiwary in Bengaluru; Editing by Shilpi Majumdar and Tom Hogue)

Follow us on our official WhatsApp channel for breaking news alerts and key updates!

   

Next In Tech News

GlobalFoundries forecasts upbeat Q4 results on strong demand from smartphone makers
Emerson sharpens automation focus with offer for rest of AspenTech in $15 billion deal
Data analytics firm Palantir jumps as AI boom powers software adoption
Tax fraud investigators search Netflix offices in Paris and Amsterdam, says source
Singapore's Keppel to buy Japanese AI-ready data centre
Tesla increases wages for staff at German gigafactory by 4%
Apple explores push into smart glasses with ‘Atlas’ user study
Japan's Kioxia sees flash memory demand almost tripling by 2028
Hacker gets into woman’s email, changes every password, tries to make purchases
Foxconn says Oct revenue +8.59% y/y, Q4 outlook good

Others Also Read