#1 Trending Cybersecurity News & Magazine
Friday, September 15, 2023
No Result
View All Result
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    DBGB Cyber Attack

    Indian Banks Under Attack: Hackers Target Dakshin Bihar Gramin Bank, City Union Bank

    Mom's Meals data breach

    Mom’s Meals Data Breach Sparks Legal Battle as 1.2 Million Affected

    MetaStealer

    MetaStealer: A Stealthy Threat Targeting macOS Users, Impersonating Adobe and TradingView

    Caesars ransomware attack

    Cyber Attacks Target Caesars Palace and MGM – Who’s Next?

    AT HOP Cyber Attack

    Massive Cyber Attack Hits Auckland’s AT HOP Smart Card System, Services Disrupted

    ransomware attacks in the uk

    Record Surge in UK Ransomware Attacks: Economic, Educational, and Regulatory Insights

    GitHub Vulnerability

    Uncovering a New GitHub Vulnerability: Guarding Against RepoJacking Attacks

    MGM Resorts cyber attack

    MGM Resorts Cybersecurity Breach: Was a 10-Minute Chat All It Took?

    Microsoft Patch Tuesday September 2023

    Microsoft Patch Tuesday September 2023 Addresses 59 Vulnerabilities, Actively Exploited Zero-Days

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Tesla Data Leak

    Massive Tesla Data Leak Exposing Over 75000 Staff Attributed to Former Employees

    Cybersecurity Primer

    Bridging the Gap: Cybersecurity Primer to Address Woes Surrounding US Government Officials

    Executive order for cybersecurity

    White House Directs Federal Agencies to Enhance Cybersecurity Amid Exposure Concerns

    AI Cyber Challenge

    Biden-Harris Administration Introduces AI Cyber Challenge, Offering $20 Million Reward

    aws agent hijack

    New Research Exposes Advanced Cyber Threat – Attackers Hijack AWS Agent to Control Endpoints

    HUB cyber security

    Investors Sue HUB Cyber Security for Misleading Statements on Mount Rainier Merger

    National Cyber Workforce and Education Strategy

    Everything You Need to Know About the National Cyber Workforce and Education Strategy (NCWES)

    Montclair cyber attack

    Montclair Cyber Attack Kicks Up the Ransom Payment Dilemma

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Emerging Tech Summit

    The Emerging Tech Summit – Saudi Arabia 2023

    Business Cybersecurity

    Prioritizing Business Cybersecurity Plans During Mergers and Acquisitions

    TimeAI Summit

    TimeAI Summit is Uniting Tech Giants and Visionaries in Dubai to Shape the Future of AI

    CyberDSA 2023

    CyberDSA 2023: Forging a Resilient Digital Future Through Unprecedented Collaboration

    Summit MENA 2023

    MENA Summit 2023: Exploring the Future of Digital Identity & Authentication

    Cyble Raises 24 Million in Series B Funding

    Cyble Raises 24 Million in Series B Funding: Leveraging AI and Threat Intelligence to Revolutionize Cybersecurity

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Bureau Raises $16.5M in Series A Funding

    Bureau Raises $16.5M in Series A Funding to Drive Global Expansion and Combat Cyber Fraud

    Cyble Partner Network

    Cyble Revolutionizes Cybersecurity Collaboration With Launch of Global Partner Program ‘Cyble Partner Network’

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    •  Cyber Security Webinar
    • Endorsed Events
  • ProductsTools
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)
SUBSCRIBE
  • MagazineDownload
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    DBGB Cyber Attack

    Indian Banks Under Attack: Hackers Target Dakshin Bihar Gramin Bank, City Union Bank

    Mom's Meals data breach

    Mom’s Meals Data Breach Sparks Legal Battle as 1.2 Million Affected

    MetaStealer

    MetaStealer: A Stealthy Threat Targeting macOS Users, Impersonating Adobe and TradingView

    Caesars ransomware attack

    Cyber Attacks Target Caesars Palace and MGM – Who’s Next?

    AT HOP Cyber Attack

    Massive Cyber Attack Hits Auckland’s AT HOP Smart Card System, Services Disrupted

    ransomware attacks in the uk

    Record Surge in UK Ransomware Attacks: Economic, Educational, and Regulatory Insights

    GitHub Vulnerability

    Uncovering a New GitHub Vulnerability: Guarding Against RepoJacking Attacks

    MGM Resorts cyber attack

    MGM Resorts Cybersecurity Breach: Was a 10-Minute Chat All It Took?

    Microsoft Patch Tuesday September 2023

    Microsoft Patch Tuesday September 2023 Addresses 59 Vulnerabilities, Actively Exploited Zero-Days

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Tesla Data Leak

    Massive Tesla Data Leak Exposing Over 75000 Staff Attributed to Former Employees

    Cybersecurity Primer

    Bridging the Gap: Cybersecurity Primer to Address Woes Surrounding US Government Officials

    Executive order for cybersecurity

    White House Directs Federal Agencies to Enhance Cybersecurity Amid Exposure Concerns

    AI Cyber Challenge

    Biden-Harris Administration Introduces AI Cyber Challenge, Offering $20 Million Reward

    aws agent hijack

    New Research Exposes Advanced Cyber Threat – Attackers Hijack AWS Agent to Control Endpoints

    HUB cyber security

    Investors Sue HUB Cyber Security for Misleading Statements on Mount Rainier Merger

    National Cyber Workforce and Education Strategy

    Everything You Need to Know About the National Cyber Workforce and Education Strategy (NCWES)

    Montclair cyber attack

    Montclair Cyber Attack Kicks Up the Ransom Payment Dilemma

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Emerging Tech Summit

    The Emerging Tech Summit – Saudi Arabia 2023

    Business Cybersecurity

    Prioritizing Business Cybersecurity Plans During Mergers and Acquisitions

    TimeAI Summit

    TimeAI Summit is Uniting Tech Giants and Visionaries in Dubai to Shape the Future of AI

    CyberDSA 2023

    CyberDSA 2023: Forging a Resilient Digital Future Through Unprecedented Collaboration

    Summit MENA 2023

    MENA Summit 2023: Exploring the Future of Digital Identity & Authentication

    Cyble Raises 24 Million in Series B Funding

    Cyble Raises 24 Million in Series B Funding: Leveraging AI and Threat Intelligence to Revolutionize Cybersecurity

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Bureau Raises $16.5M in Series A Funding

    Bureau Raises $16.5M in Series A Funding to Drive Global Expansion and Combat Cyber Fraud

    Cyble Partner Network

    Cyble Revolutionizes Cybersecurity Collaboration With Launch of Global Partner Program ‘Cyble Partner Network’

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    •  Cyber Security Webinar
    • Endorsed Events
  • ProductsTools
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Firewall Daily

MGM Resorts Cyber Attack: The Assault, Intrusion, and the ‘Unknown User’ Through the Hacker’s Lens

ALPHV noted the appearance of a user on the 'MGM victim chat' just a few hours after deploying the ransomware, as stated in their dark web post.

Vishwa Pandagle by Vishwa Pandagle
September 15, 2023
in Firewall Daily, Ransomware News
0
MGM Resorts Cyber Attack
585
SHARES
3.2k
VIEWS
Share on LinkedInShare on Twitter

The ALPHV ransomware group, suspected to be behind the MGM Resorts cyber attack, has finally spoken out regarding the security incident.

Contrary to initial assumptions, the renowned global powerhouse in the casino and resort industry, MGM Resorts, initially did not fall prey to ransomware during the cyber attack. However, they later did.

You might also like

Indian Banks Under Attack: Hackers Target Dakshin Bihar Gramin Bank, City Union Bank

Mom’s Meals Data Breach Sparks Legal Battle as 1.2 Million Affected

MetaStealer: A Stealthy Threat Targeting macOS Users, Impersonating Adobe and TradingView

ALPHV has provided clarification on its dark web platform, stating that ransomware was not deployed until a specific period had passed, during which the hackers attempted to establish communication with the MGM group.

The MGM Resorts Cyber Attack: ALPHV Ransomware Group’s Account

The much talked about MGM Resorts cyberattack has been officially confirmed as an incident involving unauthorized access and the acquisition of administrator privileges for their Okta Sync servers, by the ransomware group.

Okta, a California-based IT service management company, plays a central role in this breach. The company provides cloud-based software for ensuring secure user access, authentication, and the management of applications and websites.

MGM Resorts cyber attack
ALPHV’s leak site post (Photo: Falcon Feeds/ Twitter)

ALPHV, also known as the BlackCat ransomware group, stated, “We have made multiple attempts to reach out to MGM Resorts International.”

However, their efforts to engage with MGM Resorts officials were not reciprocated. Instead, the company opted to safeguard its networks by shutting down their systems.

ALPHV also revealed that they observed MGM Resorts taking swift action to shut down all their Okta Sync servers. It became evident to ALPHV that MGM Resorts’ IT team had detected external entities present on their Okta Agents servers.

MGM Resorts cyber attack
ALPHV’s narration of the MGM Resorts data breach (Photo: Falcon Feeds/ Twitter)

ALPHV was looking for passwords to gain access and remain unnoticed for logging in through an employee’s account credentials as part of the MGM Resorts ransomware attack.

In their post, ALPHV acknowledged encountering challenges when attempting to crack passwords from the domain controller hash dumps. This eventually resulted in the complete lockdown of Okta.

During this process, ALPHV emphasized that they successfully obtained full access to super administrator privileges within the Okta system, ultimately paving the way for the MGM Resorts cyber attack.

The hackers boasted of gaining Global Administrator privileges to their Azure tenant as well, which helped continue with the MGM ransomware attack.

MGM IT Team’s Struggle to Remove ALPHV Ransomware Group

ALPHV also elaborated on the situation where the MGM Resorts cybersecurity team attempted to evict them. “They made an attempt to evict us after discovering that we had access to their Okta environment, but things did not go according to plan.”

“On Sunday night (September 10, 2023) MGM implemented conditional restrictions that bared all access to their Okta (MGMResorts.okta.com) environment due to inadequate administrative capabilities and weak incident response playbooks,” ALPHV wrote.

At each step of the MGM Resorts cyber attack, ALPHV met with hurdles, however, they managed to gain access to the systems and noted in the dark web post where the global casino giant lagged in implementing security protocols.

MGM Resorts cyber attack
ALPHV talks about an unknown user on MGM network (Photo: Falcon Feeds/ Twitter)

ALPHV claimed that the MGM Resorts networks were infiltrated not from Sunday but from Friday, 8 September, 2023 making it the seventh day of the MGM Resorts hacking.

MGM Resorts cyber attack
MGM Resorts’ alert on Twitter

On September 11, 2023, MGM Resorts posted the above alert on its Twitter/X account, notifying the public that they had recently detected a cybersecurity issue.

MGM Resorts Could Have Handled it Better, Says ALPHV

The ransomware group stated that MGM Resorts’ network engineers could have managed the cyberattack more effectively on Saturday.

On Sunday, one day after the initial incident, ALPHV executed a ransomware attack on MGM Resorts.

They targeted over 100 ESXi hypervisors in their environment on September 11. Meanwhile, they made several unsuccessful attempts to communicate with the MGM authorities who stirred clear and remained mum.

Unknown User on MGM Resorts Network

ALPHV noted the appearance of a user on the ‘MGM victim chat’ just a few hours after deploying the ransomware, as stated in their post on their leak site concerning the MGM Resorts hack.

This user, however, remained unresponsive to ALPHV and refrained from clicking on any links sent by the cybercriminal group.

The hackers sent emails with special links to the user. At this point, ALPHV was left unsure if the user was from the company or was someone with unauthorized access.

ALPHV wanted to prevent other IT Personnel from MGM Resorts from reading the chats.

This shows that someone who was accessing or monitoring the systems of MGM Resorts learned about negotiations but did not click on any links to maintain caution and not increase the attack.

The link to download all the exfiltrated data from the MGM Resorts systems was left accessible on the same chat, to the company for perusal for two days on September 12 and 13.

Speculating about the background and identity of the unknown user, ALPHV concluded, “Since the individual in the conversation did not originate from the email but rather from the hypervisor note, as was already indicated, we were unable to confirm whether they had permission to be there.”

The uncertainty surrounding this situation explains the time taken by ALPHV to claim the MGM Resorts cyber attack if they started with their heist a week ago.

Media Disclaimer: This report is based on internal and external research obtained through various means. The information provided is for reference purposes only, and users bear full responsibility for their reliance on it. The Cyber Express assumes no liability for the accuracy or consequences of using this information.

Share this:

  • Click to share on LinkedIn (Opens in new window)
  • Click to share on Reddit (Opens in new window)
  • Click to share on Twitter (Opens in new window)
  • Click to share on Facebook (Opens in new window)
  • More
  • Click to email a link to a friend (Opens in new window)
  • Click to share on WhatsApp (Opens in new window)

Related

Tags: ALPHV MGM attackBlackCat MGM ransomware attackCasino ransomware attackHospitality sector ransomwareMGM Resorts cyber attackMGM Resorts Ransomware attackThe Cyber ExpressThe Cyber Express News
Previous Post

Indian Banks Under Attack: Hackers Target Dakshin Bihar Gramin Bank, City Union Bank

Vishwa Pandagle

Vishwa Pandagle

Vishwa Pandagle is a Technical Writer at The Cyber Express. She writes cybersecurity news related to data breaches, ransomware, phishing, and best practices among others. She also writes about cybersecurity developments and likes interacting with experts in this field. When not working, she likes self-reflecting, meditating, volunteering, and going for long walks.

Related Posts

DBGB Cyber Attack
Firewall Daily

Indian Banks Under Attack: Hackers Target Dakshin Bihar Gramin Bank, City Union Bank

by Vishwa Pandagle
September 14, 2023
Mom's Meals data breach
Data Breach News

Mom’s Meals Data Breach Sparks Legal Battle as 1.2 Million Affected

by Ashish Khaitan
September 14, 2023
MetaStealer
Firewall Daily

MetaStealer: A Stealthy Threat Targeting macOS Users, Impersonating Adobe and TradingView

by Ishita Tripathi
September 14, 2023
Caesars ransomware attack
Data Breach News

Cyber Attacks Target Caesars Palace and MGM – Who’s Next?

by Ashish Khaitan
September 14, 2023
AT HOP Cyber Attack
Firewall Daily

Massive Cyber Attack Hits Auckland’s AT HOP Smart Card System, Services Disrupted

by Vishwa Pandagle
September 14, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Latest Issue is Out. Subscribe Now



Follow Us On Google News

Latest Cyber News

DBGB Cyber Attack
Firewall Daily

Indian Banks Under Attack: Hackers Target Dakshin Bihar Gramin Bank, City Union Bank

September 14, 2023
Mom's Meals data breach
Data Breach News

Mom’s Meals Data Breach Sparks Legal Battle as 1.2 Million Affected

September 14, 2023
MetaStealer
Firewall Daily

MetaStealer: A Stealthy Threat Targeting macOS Users, Impersonating Adobe and TradingView

September 14, 2023
Caesars ransomware attack
Data Breach News

Cyber Attacks Target Caesars Palace and MGM – Who’s Next?

September 14, 2023

Categories

Web Stories

Top 10 CISOs to Follow in 2023
Top 10 CISOs to Follow in 2023
Top 10 Ransomware Gangs in 2023
Top 10 Ransomware Gangs in 2023
Top 5 IoT Security Risks in 2023
Top 5 IoT Security Risks in 2023
Top 10 CTF Platforms in 2023
Top 10 CTF Platforms in 2023
Types of Risks Covered by Cyber Insurance
Types of Risks Covered by Cyber Insurance

About

The Cyber Express by Cyble

#1 Trending Cybersecurity News and Magazine

The Cyber Express  by Cyble is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

 

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

For Events & Conferences related information: [email protected]

 

Quick Links

  • About Us
  • Advertise With Us
  • Contact Us
  • Editorial Calendar

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
555 North Point Center E
Alpharetta, GA 30022, USA.

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

Subscribe to Our Feed

RSS Feeds

Follow Us On Google News
  • Privacy Statement
  • Terms of Use
  • Write For Us

© 2023 The Cyber Express (Cybersecurity News and Magazine) | By Cyble Inc.

No Result
View All Result
  • Magazine
  • Firewall Daily
  • Essentials
    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    •  Cyber Security Webinar
    • Endorsed Events
  • Products
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)

© 2023 The Cyber Express (Cybersecurity News and Magazine) | By Cyble Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
Top 10 CISOs to Follow in 2023 Top 10 Ransomware Gangs in 2023 Top 5 IoT Security Risks in 2023 Top 10 CTF Platforms in 2023 Types of Risks Covered by Cyber Insurance