MGM Resorts cyberattack disrupts operations; company discloses material financial impact
MGM Resorts disclosed a cybersecurity issue in September 2023 that disrupted certain company systems and operations, prompting incident response actions and public communications through SEC filings. In later SEC disclosures, MGM estimated the incident would reduce third-quarter adjusted property EBITDAR by approximately $100 million. The event is a clear example of a cyber incident driving both immediate operational disruption in hospitality and a quantified negative impact on financial results reported to investors.
First reported September 12, 2023Outagemed overall confidence
MGM Resorts International (corporate operations and IT systems)
Initial access
unknown
stolen_creds
Impact
service_disruption
financial_loss
extortion
unknown
Attribution
unknownlow confidence
Public reporting speculated on actor groups; definitive attribution is not established in the cited SEC filings.
CVEs and ATT&CK
No CVE or ATT&CK association is captured in this curated record.
Mitigations
Now
Enforce phishing-resistant MFA for workforce and privileged accountsReduces successful account takeovers from stolen passwords and common social engineering techniques.
Soon
Harden helpdesk and password reset workflowsPrevents attackers from using social engineering to reset MFA or regain access via the identity recovery channel.
Later
Apply conditional access and session risk controls (device posture, geo, impossible travel)Limits account abuse by requiring stronger signals for high-risk sign-ins and reducing lateral access after compromise.
Detection ideas
Alert on anomalous authentication patterns
Flag first-time device logins, new geo/ASN, impossible travel, and sign-ins immediately followed by privilege escalation or access to sensitive apps.