Casino giant Caesars Entertainment reports cyberattack; MGM Resorts says some systems still down

Advertisement

Advertise with us

LAS VEGAS (AP) — Casino company Caesars Entertainment on Thursday joined Las Vegas gambling rival MGM Resorts International in reporting that it was hit by a cyberattack, but added in a report to federal regulators that its casino and online operations were not disrupted.

Read this article for free:


or

Already have an account? Log in here »

To continue reading, please subscribe:

Subscribe and receive a limited-edition Free Press branded hat or tote.

Digital Subscription

One year of digital access for only $205*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles

*First annual payment billed as $205.00 + GST for one year. This annual subscription will automatically renew at $233.00 + GST every 52 weeks (10% off the regular annual price of $259.35). Offer available to new and qualified returning subscribers only. Cancel any time.

To continue reading, please subscribe:

Add Free Press access to your Brandon Sun subscription for only an additional

$1 for the first 4 weeks*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles
Start now

*Your next Brandon Sun subscription payment will increase by $1.00 and you will be charged $17.95 plus GST for four weeks. After four weeks, your payment will increase to $24.95 plus GST every four weeks.

Hey there, time traveller!
This article was published 14/09/2023 (1121 days ago), so information in it may no longer be current.

LAS VEGAS (AP) — Casino company Caesars Entertainment on Thursday joined Las Vegas gambling rival MGM Resorts International in reporting that it was hit by a cyberattack, but added in a report to federal regulators that its casino and online operations were not disrupted.

The Reno-based publicly traded company told the federal Securities and Exchange Commission that it could not guarantee that personal information about tens of millions of customers was secure following a data breach Sept. 7 that may have exposed driver’s license and Social Security numbers of loyalty rewards members.

“We have taken steps to ensure that the stolen data is deleted by the unauthorized actor,” the company said, “although we cannot guarantee this result.”

People walk by the MGM Grand hotel-casino Wednesday, Sept. 13, 2023, in Las Vegas. A
People walk by the MGM Grand hotel-casino Wednesday, Sept. 13, 2023, in Las Vegas. A "cybersecurity issue" led to the shutdown of some casino and hotel computer systems at MGM Resorts International properties across the U.S., a company official reported Monday, Sept. 11, 2023. (AP Photo/John Locher)

Brett Callow, threat analyst for the New Zealand-based cybersecurity firm Emsisoft, said it was not clear if a ransom was paid or who was responsible for the intrusion — and for the attack reported Monday by MGM Resorts.

“Unofficially, we saw a group called Scattered Spider claimed responsibility,” Callow said. “They appear to be native English speakers under the umbrella of a Russia-based operation called ALPHV or BlackCat.”

Scattered Spider also is known as UNC3944, said Charles Carmakal, chief technical officer at cybersecurity firm Mandiant. He called the group “incredibly disruptive and aggressive” in recent targeting of hospitality and entertainment organizations.

“They leverage tradecraft that is challenging for many organizations with mature security programs to defend against,” Carmakal said in a statement.

Mandiant said in a blog analysis published Thursday the group uses SMS text phishing and phone calls to help desks to attempt to obtain password resets or multifactor bypass codes.

“This relatively new entrant in the ransomware industry has hit at least 100 organizations, most of them in the U.S. and Canada,” Mandiant said.

Caesars is the largest casino owner in the world, with more than 65 million Caesars Rewards members and properties in 18 states and Canada under the Caesars, Harrah’s, Horseshoe and Eldorado brands. It also has mobile and online operations and sports betting. Company officials did not respond to emailed questions from The Associated Press.

The company told the SEC that loyalty program customers were being offered credit monitoring and identity theft protection.

There was no evidence the intruder obtained member passwords or bank account and payment card information, the company reported, adding that operations at casinos and online “have not been impacted by this incident and continue without disruption.”

The disclosure by Caesars came after MGM Resorts International, the largest casino company in Las Vegas, reported publicly on Monday that a cyberattack that it detected Sunday led it to shut down computer systems at its properties across the U.S. to protect data.

MGM Resorts said reservations and casino floors in Las Vegas and other states were affected. Customers shared stories on social media about not being able to make credit card transactions, obtain money from cash machines or enter hotel rooms. Some video slot machines were dark.

MGM Resorts has has about 40 million loyalty rewards members and tens of thousands of hotel rooms in Las Vegas at properties including the MGM Grand, Bellagio, Aria and Mandalay Bay. It also operates properties in China and Macau.

People walk by the MGM Grand hotel-casino Wednesday, Sept. 13, 2023, in Las Vegas. Casino operator MGM Resorts International said Tuesday that resorts are open and an investigation is continuing after what it called a “cybersecurity issue” led to the shutdown of computer systems at company properties across the U.S. (AP Photo/John Locher)
People walk by the MGM Grand hotel-casino Wednesday, Sept. 13, 2023, in Las Vegas. Casino operator MGM Resorts International said Tuesday that resorts are open and an investigation is continuing after what it called a “cybersecurity issue” led to the shutdown of computer systems at company properties across the U.S. (AP Photo/John Locher)

A company report on Tuesday to the SEC pointed to its Monday news release. The FBI said an investigation was ongoing but offered no additional information.

Some MGM Resorts computer systems were still down Thursday, including hotel reservations and payroll. But company spokesman Brian Ahern said its 75,000 employees in the U.S. and abroad were expected to be paid on time.

Callow, speaking by telephone from British Columbia, Canada, called most media accounts of the incidents speculative because information appeared to be coming from the same entities that claim to have carried out the attacks. He said recovery from cyberattacks can take months.

Callow pointed to reports that he called “plausible” that Caesars Entertainment was asked to pay $30 million for a promise to secure its data and may have paid $15 million. He also noted that the company did not describe in the SEC report the steps taken to ensure that the stolen data was secure.

The highest ransom believed to have been paid to cyber-attackers was $40 million by insurance giant CNA Financial, Callow said, following a data breach in March 2021.

“In these cases, organizations basically pay to get a ‘pinky promise,’” he said. “There is no way to actually know that (hackers) do delete (stolen data) or that it won’t be used elsewhere.”

____

Associated Press technology writer Frank Bajak in Boston contributed to this report.

Report Error Submit a Tip

More Stories

Duo accused in random Osborne Village attacks no strangers to police

Dean Pritchard and Chris Kitching 5 minute read Preview

Duo accused in random Osborne Village attacks no strangers to police

Dean Pritchard and Chris Kitching 5 minute read Tuesday, Oct. 6, 2026

A man arrested following a violent, random attack on two men in Osborne Village late Sunday night was released from jail a week earlier after a dozen charges, including crimes of violence, were stayed against him, court records show.

A man in his 40s was sent to hospital in critical condition and another man in his 20s in stable condition following separate attacks shortly before midnight in the vicinity of River Avenue and Osborne Street.

Police have charged Reginald Owen, 26, and Meaghan Owen, 32, both from Little Grand Rapids, with assault with a weapon and aggravated assault. They both remain in custody.

Court records show Reginald Owen was sentenced Sept. 24 to 30 days time served after pleading guilty to simple possession of magic mushrooms. Owen remained in custody until the following day when he was set to apply for bail on charges including assault, sexual assault, choking to overcome resistance, pointing a firearm, and carrying a concealed weapon.

Read
Tuesday, Oct. 6, 2026

Whistleblower pharmacist fined for misconduct after complaint

Nicole Buffie 5 minute read Preview

Whistleblower pharmacist fined for misconduct after complaint

Nicole Buffie 5 minute read Tuesday, Oct. 6, 2026

A Manitoba pharmacist who made complaints against a colleague that led to sanctions against him has now also been fined due to her own conduct.

Read
Tuesday, Oct. 6, 2026

Manitoba pharmacists push for increased role in administration of vaccines

Chris Kitching 6 minute read Preview

Manitoba pharmacists push for increased role in administration of vaccines

Chris Kitching 6 minute read Updated: 8:54 PM CDT

Manitoba’s public health officials are preparing for influenza season to peak earlier than usual amid concerns about declining uptake for flu and COVID-19 vaccinations.

While the season started early in some provinces, including Ontario and B.C., Dr. Brent Roussin, Manitoba’s chief public health officer, said it’s too soon to conclusively say if the same will happen here.

“But certainly seeing what’s around us and seeing an uptick (in cases) here, it’s making a concern it might be an early year,” he told the Free Press on Thursday.

Manitoba’s flu season usually peaks in late December, with the vaccination campaign continuing into the new year.

Read
Updated: 8:54 PM CDT

Dozens of Uber, Lyft drivers switched to cheaper insurance coverage: MPI probe

Erik Pindera 5 minute read Preview

Dozens of Uber, Lyft drivers switched to cheaper insurance coverage: MPI probe

Erik Pindera 5 minute read Updated: 6:09 PM CDT

Ride-service drivers have been defrauding Manitoba Public Insurance by improperly insuring their vehicles as for personal use.

The public insurer and the City of Winnipeg, which regulates ride-hailing services like Uber and Lyft, discovered the widespread fraud after MPI conducted a review in December last year.

“When a driver changes their coverage from ride-share insurance to a personal vehicle coverage and continues to operate as a ride-share driver, that is fraud, plain and simple,” said MPI chief executive officer Satvir Jatana at a news conference Thursday.

MPI’s review looked at a random sample of 408 ride-hailing vehicles and found 108 were operating without the proper vehicle-for-hire insurance coverage. In order to register with the city as a ride-service driver, a vehicle must have such insurance and proof must be provided to the ride-booking company.

Read
Updated: 6:09 PM CDT

Accused in Brandon sword attack pleads not guilty

Tessa Adamski 5 minute read Preview

Accused in Brandon sword attack pleads not guilty

Tessa Adamski 5 minute read 7:50 PM CDT

BRANDON — A youth accused of severely injuring a student in a targeted sword attack at a Brandon high school detailed a “mass murder-suicide plan” months before the incident.

The plan mimicked a racially motivated school killing of three immigrants in Sweden.

The 17-year-old boy unexpectedly pleaded not guilty to nine charges on Tuesday during a scheduled pretrial hearing in Brandon’s Court of King’s Bench.

The teen, who can’t be identified under the Youth Criminal Justice Act, is charged with three counts of attempted murder, aggravated assault, two counts of assault with a weapon, wearing a disguise with intent and two counts of possessing a weapon for a dangerous purpose in relation to the June 10, 2025 attack at Ecole secondaire Neelin High School.

Read
7:50 PM CDT

Zach is back

Taylor Allen 5 minute read Preview

Zach is back

Taylor Allen 5 minute read 6:40 PM CDT

You can knock Zach Collaros down, but he’s going to get back up.

The starting quarterback for the Winnipeg Blue Bombers was a full participant at Thursday’s practice — a first since suffering a head injury in the Banjo Bowl.

The 38-year-old will be under centre when the Blue and Gold (7-8) host the Calgary Stampeders (8-8) on Saturday.

Considering his well-documented history of injuries above the shoulders, there’s been a lot of speculation on the outside about whether Collaros would — or should — return this season.

Read
6:40 PM CDT