• Industry
    • Opinion
    • Features
      • iGaming Data
      • Sports Betting Data
    • Finance
    • Online Casinos
    • Podcast

      News

      MGM Resorts Fights FTC Over Cyberattack Investigation

      A lawsuit filed in federal court Monday asserts that the FTC's inquiry oversteps its authority and violates MGM's Fifth Amendment rights.

      By Erik Gibbs

      Last updated: September 9, 2024

      2 min

      A hacker typing on a keyboard behind a screen of computer code

      MGM Resorts International is taking on the Federal Trade Commission (FTC). Reuters reports that MGM hopes to halt an investigation into the casino operator’s handling of a cyberattack that targeted its operations last year.

      The lawsuit, filed in federal court, asserts that the FTC’s inquiry oversteps its authority and violates MGM’s Fifth Amendment rights. The casino operator contends that the FTC, led by Chairwoman Lina M. Khan, who personally experienced the cyberattack’s effects, is unfairly targeting the company based on regulations that do not apply to its operations.

      MGM’s lawsuit highlights a conflict of interest, according to the company, alleging that Chairwoman Khan’s direct involvement in the cyberattack — having been a guest at an MGM property during the incident — compromises the FTC’s objectivity. The company further claims that the FTC’s actions deprived it of its right to a fair hearing and equal treatment under the law, as guaranteed by the Due Process Clause of the Fifth Amendment.

      There was a funny story last fall where FTC chair Lina Khan was checking into an MGM hotel and the desk employee said their system was down and instructed her to write her credit card info on paper. Khan, literally the person in charge of ensuring companies protect sensitive… https://t.co/gWKHxrmaw9

      — Paul McLeod (@pdmcleod) April 16, 2024

      The FTC’s investigation aims to scrutinize MGM’s response to the hack, which disrupted the company’s IT systems and affected thousands of guests and customers. It led to a 10-day shutdown of computer systems that disrupted hotel reservations and credit card processing.

      The regulatory body issued a Civil Investigative Demand (CID) last week, which compels MGM to provide extensive information spanning several years. MGM argues that this demand is excessive and irrelevant and that the rules the FTC cited in its complaint — the “Safeguards Rule” and the “Red Flags Rule” — are designed for financial institutions, which MGM does not classify as.

      A massive cyber headache

      The cyberattack occurred last September and was widely publicized. An unauthorized third party accessed the personal information of MGM customers, including names, contact details, and, in some cases, Social Security and passport numbers. However, MGM maintains that no financial data was compromised. In response to the breach, MGM took immediate steps to secure its systems and launched an investigation with cybersecurity experts, while also coordinating with law enforcement.

      The repercussions of the cyberattack were significant for MGM, causing operational disruptions across multiple properties. MGM estimates that the incident impacted its adjusted property EBITDAR (earnings before interest, taxes, depreciation, amortization, and restructuring or rent costs) for the quarter by approximately $100 million, despite reporting record revenue.

      MGM wasn’t the only target of hackers last year. Caesars Entertainment also experienced a significant attack targeting its loyalty program database, compromising personal information such as Social Security numbers and driver’s license numbers. Caesars eventually acknowledged that it paid a $15 million ransom after initially denying making any deals.

      Cyberattacks on the rise

      The casino industry has faced a significant challenge with a rise in cyberattacks over the past few years. Experts have warned that such attacks are likely to continue, urging businesses to enhance their security protocols and prepare for potential threats.

      Attacks in the US by the 10 most active ransomware groups July 2022 - June 2023
      Source: Malwarebytes 2023 State of Ransomware

      The hacks MGM and Caesars, as well as numerous other casinos, dealt with were reportedly the work of Scattered Spider, a global hacking group also identified as UNC3944, among other aliases. It emerged around May 2022, and since its introduction, it has launched sophisticated cyberattacks on major corporations, particularly in the casino and gambling sectors.

      Scattered Spider’s methods are diverse, ranging from social engineering to exploiting security vulnerabilities. While the exact membership of the group remains elusive, it is believed to include operatives based in the U.S. and the U.K., with affiliations to other cybercriminal entities such as Russia-based ALPHV.

      ALPHV, also known as BlackCat, was behind the Colonial Pipeline hack in 2021 and others. Scattered Spider, according to the FBI, reached out to the group in an effort to grow its capabilities, leading to the recent string of attacks.

      The financial impact of these attacks is substantial. IBM stated that the average attack in 2023 cost companies $4.45 million. That was a 15% increase from 2020.

      Get Weekly Email Updates

      Covering all aspects of regulated U.S. online casinos, iGaming, sweepstakes, and more

      Related Posts

      new york skyline

      New York Gaming Board Aiming To Extend Casino Bid Deadline To June 2025

      borgata fireworks

      Online Casino Revenue Still Booming in New Jersey, Setting Another Record (Just Barely) In November

      justice lady statue

      Report: New Jersey Woman Sues DraftKings After Her Husband Loses $942K In Family Money

      Jordan Maynard Named Chair Of The Massachusetts Gaming Commission

      Recommended Read

      casino live stream

      Industry

      The Allure And The Antics Of Kick Casino Streamers

      There’s More…

      iowa state iowa football

      News

      Iowa College Athletes Want To Adjust Their Lawsuit Over Sports Betting Investigation

      September 9, 2024

      Matthew Bain

      who office

      News

      World Health Organization Raises Global Alarm On Responsible Gambling

      December 4, 2024

      Erik Gibbs

      us supreme court

      News

      Supreme Court Declines To Hear Florida Sports Betting Case, Leaving Seminole Tribe Monopoly Intact

      The Supreme Court's decision leaves the tribe's exclusive right to offer online sports betting in the Sunshine State uncontested, for now.

      September 9, 2024

      Erik Gibbs

      police cars

      News

      Authorities Bust Illegal Gambling Operations In Connecticut, Mississippi

      September 9, 2024

      Laura Corkhill

      Get Weekly Email Updates

      Covering all aspects of regulated U.S. online casinos, iGaming, sweepstakes, and more

      • About
      • Contact
      • Privacy
      • Terms
      • Disclosure
      • Responsible Gaming

      © 2025 Casino Reports. Web Design by Fhoke.