TechDogs-"Security Concerns Rise As The Hospitality Industry Comes Under Attack From Ransomware Actors!"

Cyber Security

Security Concerns Rise As The Hospitality Industry Comes Under Attack From Ransomware Actors!

By Lakshana Raichandani

Updated on Fri, Sep 15, 2023

Overall Rating
“Play long enough, you never change the stakes, the house takes you. Unless, when that perfect hand comes along, you bet big, and then you take the house.”

Do you remember this iconic dialogue by Danny Ocean (played by George Clooney) in the 2001 movie - Ocean's Eleven? It was a pretty intense movie, starring big names and an elaborate heist plotline. However, it looks like someone took the dialogue too seriously.

Attempting to “take the house”, a hacking group deployed a ransomware attack on two major hotels on the Las Vegas strip – Ceasars Entertainment and the multi-hotel owner MGM Resorts International.

(FYI, the three hotel casinos the Ocean’s Eleven crew hit were the Bellagio, Mirage and MGM Grand –all operated by MGM Resorts International in real-life. Coincidence?)

So, what happened to these two leading hospitality leaders?

Let’s explore:
 

What Happened To Ceasars Entertainment And MGM Resorts International?

 
  • MGM Resorts International, the $14 billion hospitality provider that operates more than 30 hotel and gaming venues worldwide, fell victim to a hacking group called Scattered Spider.

  • While the giant said it had shut some systems to contain a “cybersecurity issue”, the attack caused its systems to be shut for over three days.

  • As per reports, the initial shutdown impacted services such as reservation systems, booking systems, email systems, in-room TV services, phone lines, hotel electronic key card systems and even the casino floors!

  • Reportedly, US law enforcement officials have started a probe into the breach.

  • Days before MGM was attacked, Ceasars Entertainment was hit, with the attackers reportedly demanding $30 million. Ultimately, the company agreed to pay $15 million to the hackers.

  • While the payment to the hackers will be partially mitigated by cyber insurance policies, Ceasars Entertainment believes the attack and payment won’t have a material effect on the company’s bottom line.

  • Both organizations witnessed a fall of shares following the attack announcement.
 

What Is Scattered Spider?

 
  • Scattered Spider AKA UNC3944, has targeted telecom and BPO (business process outsourcing) companies previously and has now moved to critical infrastructure organizations.

  • According to reports, analysts believe that the group uses social engineering to gain access to login credentials and one-time passwords to get past authentication processes.

  • Speaking on the group, Charles Carmakal, CTO at Mandiant Intelligence (now part of Google Cloud), said, "Although members of the group may be less experienced and younger than many of the established multifaceted extortion/ransomware groups and nation state espionage actors, they are a serious threat to large organizations in the US."

  • He added saying the group is “one of the most prevalent and aggressive threat actors impacting organizations in the United States today,"

   

What Did MGM Say?

 
  • In a post on X (which has since been deleted) and through a press release published on its website, MGM said, “MGM Resorts recently identified a cybersecurity issue affecting some of the Company's systems. Promptly after detecting the issue, we quickly began an investigation with assistance from leading external cybersecurity experts.”

  • [contd.] “We also notified law enforcement and took prompt action to protect our systems and data, including shutting down certain systems. Our investigation is ongoing, and we are working diligently to determine the nature and scope of the matter.”

 
Of course, it isn’t just hotels and casinos that are victims of ransomware attacks. Did you know the very first ransomware attack happened all the way back in 1989! What did it cost? A measly $189. Even inflation-adjusted the value comes to around $468.

We’ve come a long way from there, with the number of worldwide ransomware attacks totaling 236.1 million, just in the first half of 2022, according to a report.

Coming to 2023, just the second quarter witnessed 1,387 organizations affected by ransomware data leaks; a 64% increase from the previous quarter, which was already a record-breaker.

Obviously, businesses and other organizations need to take ransomware attacks seriously. Businesses, especially in the hospitality industry, need to evaluate their security providers and ensure their security products don’t possess vulnerabilities (read more) or try innovative methods (read more) to enhance resilience against ransomware attacks.

What measures do you think businesses can take to protect themselves? What more can security software companies do?

Let us know in the comments below!

First published on Fri, Sep 15, 2023

Enjoyed what you read? Great news – there’s a lot more to explore!

Dive into our content repository of the latest tech news, a diverse range of articles spanning introductory guides, product reviews, trends and more, along with engaging interviews, up-to-date AI blogs and hilarious tech memes!

Also explore our collection of branded insights via informative white papers, enlightening case studies, in-depth reports, educational videos and exciting events and webinars from leading global brands.

Head to the TechDogs homepage to Know Your World of technology today!

Disclaimer - Reference to any specific product, software or entity does not constitute an endorsement or recommendation by TechDogs nor should any data or content published be relied upon. The views expressed by TechDogs' members and guests are their own and their appearance on our site does not imply an endorsement of them or any entity they represent. Views and opinions expressed by TechDogs' Authors are those of the Authors and do not necessarily reflect the view of TechDogs or any of its officials. While we aim to provide valuable and helpful information, some content on TechDogs' site may not have been thoroughly reviewed for every detail or aspect. We encourage users to verify any information independently where necessary.

Loading comments...

  • Dark
  • Light