MGM losing up to $8.4M a day due to cyberattack, analyist says
reviewjournal.com
reviewjournal.com
> I encourage you to walk through some casinos and take stock of what you see.
I have spent a lot of time at casinos with family members who love eating, drinking, smoking, and gambling. Know what I've seen? I've seen that gambling is the only one of the four that hasn't killed at least one of my family members.
Edit: I found it. It looks more professionally edited and lengthy than when I first came across it in 2010(!).
Link: https://www.themorgandoctrine.com/2010/11/draft-01-cyber-pri...
The Cyber Privateer Code (draft 02—updated on 6/28/2013): - Any unauthorized attempt to access your computer or phish your data access privileges constitutes a crime punishable by the looting of the attacker's assets by an authorized cyber privateer. All assets. Within 6 months of the attack.
- If it is determined that the attacker is acting under explicit instructions from a larger organization or government, the assets of that organization or government are also forfeit to the extent that an authorized cyber privateer may confiscate them within a six month period of the original motivating attack. All assets.
- The individual whose assets were seized by a cyber privateer—or the publicly and legally designated spokesperson for the organization or government whose assets were seized by the cyber privateer—has the "right of parley" with the head of the cyber privateering organization, such meeting to take place online in a two-way video conference, such conference to be publicly recorded by one or both parties and before the disposition of the booty but no later than 10 days from the confiscation.
- Innocent victims whose assets are directly and mistakenly confiscated by cyber privateers (and whose funds are not returned within 10-days after the parley) shall be compensated in an amount equal to four times their loss, with interest accruing on the restitution amount at the rate of twelve percent per annum. This does not include victims of the cyber criminals, since they were already victimized.
- Notifications and requests for parley must be unambiguously left by the cyber privateer so as to allow the right of parley to be exercised in a timely fashion.
*These rules would of course lead to the worlds end in any significant conflict, imo. But it would certainly be fun for a minute.
Example:
https://www.bloomberg.com/news/articles/2023-09-13/caesars-e...
Caesars Entertainment Inc. paid tens of millions of dollars to hackers who broke into the company’s systems in recent weeks and threatened to release the company’s data, according to two people familiar with the matter.
Hacking gangs typically ask to be paid in cryptocurrency if they demand a ransom.
I don't want to live in a world with 100% anonymous and untraceable payments.
Cash is equally as capable of this, though. The hackers in this situation could demand cash and practically nothing would change about the technical aspects of their attack.
They would have to travel from e.g. Russia to Las Vegas to pick up the cash though. Or, I suppose, demand delivery of cash to Russia, or some other place. Whichever way, it's a lot easier for law enforcement. Suddenly a particular country is responsible.
BTC makes dealing with all of that a (potentially automated) bash one-liner.
Check out War is a Racket, by US general Smedley Butler
Also the Snowden documents and the whole Asange/Wikileaks case
There is an urgent need to have effective international law-enforcement and justice.
What makes you think any other organization given such privilege would do any better with it than the US? Even if they started out with good intentions, that kind of power will inevitably corrupt them.
Embrace multipolarity. Benevolent, wise and just unipolarity will never happen.
Powerful also does not mean unipolar/dominant. Checks and balances can exist. That's how the US government was initially designed.
Countries already use criminals as political tools to advance their goals on the world stage. What makes you think expanding these efforts will somehow change existing geopolitical behavior?
All systems of law break down into the imposers, and the imposed upon. You don't have to impose anything on the voluntarily compliant, but what about those that refuse? Are you going to invade or kill innocent people just because a few leaders don't want to play by your rules?
Sanctions don't work for their intended political purpose. The only reason politicians talk about them is because it enables their corporate masters to swoop into markets and make a lot of money. (And if you disagree, I ask you find a study pointing to how sanctions were politically successful.)
What does that have to do with it? We should expect more of international institutions in a multipolar world.
It's urgent to anyone that has had to deal with ransomware gangs.
It's urgent for countries suffering from violent cartels.
It's urgent for Canada, which just accused India of assassinating one of its citizens on Canadian soil.
And so on.
The whole reason why the world went from unipolar to multipolar is because the existing international organizations failed. What you're missing is these international organizations are political instruments used to obstruct and hinder Russia and China's development. The people in those countries don't share your supposition that more international organizations are a good thing.
> It's urgent to anyone that has had to deal with ransomware gangs.
What makes you think an international organization can do anything about ransomware? It's existed in this form for over a decade and nobody has done anything about it.
> It's urgent for countries suffering from violent cartels.
Why hasn't some international organization been formed to handled this then? Multipolarity is a very recent.
> It's urgent for Canada, which just accused India of assassinating one of its citizens on Canadian soil.
Do you think Canada is going to war with India over this?
They "failed" because they were gutted by a covert, powerful and violent "right-wing" alliance (imperialists, capitalists, white supremacists, all who felt tremendously victimized by recent global events incl. rise of communism). They were not about to throw away centuries of dominance to share international power with "inferior" classes of human.
The UN was rather effective in its initial decades.
Do you really think Hammarskjold, Kennedies, African(-American) leaders getting assassinated en masse in the 1960s was a spate of random coincidence? They were all united in opposing this covert alliance.
But the world is different now, the Global South is decisively emerging from under the imperial boot and multipolarity has a real chance.
It seems no answer can satisfy you.
You're saying we need more international organizations (or more powerful ones) to prevent the problems described. But when we do form these international organizations, and they don't do exactly like you hoped it's because of intangible reasons that cannot be falsified.
> The UN was rather effective in its initial decades.
The League of Nations, which precedes the UN, was rather effective in the 1920s and didn't include the USA. It also completely dropped the ball by 1930. Historians partially blame the League of Nations for the outbreak of second World War.
> Do you really think Hammarskjold, Kennedies, African(-American) leaders getting assassinated en masse in the 1960s was a spate of random coincidence? They were all united in opposing this covert alliance.
You're vacillating between wanting more powerful international organizations, but at the same time don't want international organizations wielding their power in ways you personally don't approve of.
What does this add?
> intangible reasons that cannot be falsified.
I assure you there is nothing intangible about a clear pattern of high-profile assassinations, to say nothing of other related global events.
> You're vacillating between wanting more powerful international organizations, but at the same time don't want international organizations wielding their power in ways you personally don't approve of
You really can't see the difference between overt, ratified international institutions, and shadowy, nameless, violent special-interest groups? Come now.
What would convince you they're not conspiring together?
As for international organizations, my point is that even ratified and official organizations are not immune to political pressures and special interests. How do we ensure transparency, efficacy, and fairness when the existing entities can't do that sufficiently well to maintain unipolarity?
When you have geo replicas and point-in-time restoration capabilities which can synchronously bring 100% of the business back from the dead in a matter of seconds/minutes...
How many $8.4m days before a complete rewrite of all systems would be justified? If you are going to entertain a rewrite, why not use one system to rule them all so you can audit one thing and move on with life?
This industry does not seem like a good fit for non-traditional technology stacks. I'd strongly consider putting my entire casino on a mainframe if I could. Any vendor who indicates a lack of willingness for integration with that tech stack would be instantly disqualified from selection. I feel like this is a really good technology bullshit filter for the kind of industry MGM is operating in. If it's not good enough for Visa or Amex, it's not good enough for a gambling operation.
I too have a theory that you could get away with this and come out ahead of the industry. The problem is no CEO has the balls to try it in FinTech or any other heavily regulated industry.
Plus these guys apparently got majorly pwned. I don't think any particular blend of stack was to blame, more likely they have a lord-of-the-flies driven technology "architecture" and simply hoped nothing bad ever happened.
Even if all their business data was 100% retrievable, they are losing money every day that customers are wandering around a casino full of darkened screens, and playing a working slot or getting a drink involves waiting 20 minutes for an employee with a pencil, notebook and a handful of cash.
They won't make the same mistake twice and will build a comprehensive cybersecurity program, and it will succeed. Up until someone questions this cost and they forgot what they are paying for because everything was so smooth and repeat the cycle.
The objective of security is risk identification and management, not creating an impervious barrier for potential adversaries.
You couldn’t have said it better.
Just ask any CISO if they would bet their job on surviving a $1M unrestricted red team exercise with a year-long timeframe. They would all be scared shitless by the thought. I bet if you asked the CISO of MGM three days before the attack: "How much would it cost to hack MGM and cripple operations?" they would answer like every other CISO I have heard answer that question and say something on the order of $100K. They know it does not work; they are there to be sacrificed and just hope it does not happen on their watch.
Keep in mind that amounts to around 100 person-years of dedicated hacking labor. I get a team of 50 and 2 years to achieve total compromise. I get to burn 5-10 zero click RCE zero-days. The idea that any of the commercial cybersecurity companies or any commercial IT organization could design a system that could resist such an attack is laughable. This is not a question of resources, it is one of ability.
I agree, compliance is not an above-average security program. But an security program that is merely above-average is woefully underprepared for the modern threat landscape. You need a security program 100x better than “best practices” to stand a meaningful chance and you are not finding that amongst the charlatans in the big cybersecurity players.
Speaking from my experience, many don't understand the threats even after an incident. The reaction is often to add 'more security' under any name. More restrictive policies, more scanning, more layers of MFA - just blindly layering on things because it's seen as 'more secure' without properly understanding how it affects risk is an awful approach to managing security.
They have an incredibly crusty, buggy billing system written in PowerBuilder, and I swear it's a holdover from the Voice stream days
Disclaimer: Worked there in Tech Support.
And then, when it does, they blame the people who were pointing out the risks and suggesting solutions rather than the people who were ignoring those people the whole time.
Unless they don't have cyber insurance
I'm curious to see how this plays out. After all, if MGM is audited and found to have been negligent, would insurance pay out at all?
As long as the auditors OK'd it then the insurance should pay out. Unless they can show that MGM intentionally lied in the information they gave the auditors -- which will surely now be gone through with a fine-toothed comb.
(See that HN thread from a couple of days ago wondering if they were personally liable for fraud for producing a document lying about pentesting.)
This way, even if you have a snapshot from 7 days ago, it's also infected.
Or even worse they have physical access to the backup server/storage and just delete backups infect them as well.
Some middle-manager somewhere, probably.
1. Restoring networks, servers, third party services with knowledge that anything you restore could be compromised as well. Keys
2. The attackers will then threaten to dump all of your private information.
It is more than just restoring data, it is restoring and resetting your entire infrastructure. And most places have backups, but they don't practice entire restores
Or worse, they only practice part of it. Only once in my career have I seen a "restore.txt" that didn't start with something along the lines of "connect to $server".
Ok, that assumes a LOT is already in place. Where is the "restore.txt" that goes over how to get $network up so that I can resolve the IP(s) for the server I need to restore?
I can't prove it, but I suspect that most businesses know deep down that they _cant_ do a "black start" and they know that even a practice run is likely to find some pretty basic and embarrassing issues that will just be too costly to address.
several years ago.
hopefully there were no externally managed dependencies, as those can change.
hopefully the documentation was entirely written down, not just 80%, with that last 20% having retired, been laid off, or died since then.
how many companies are left at that point?
https://mgmresorts.okta.com/app/mgmresortsprod_neocaseemploy...
It's a reasonable perspective from accounting and, in my mind, a reasonable shorthand. For a more literal version of losing, people would be saying misplacing or stealing.
It doesn't seem unreasonable to say they are, in fact, losing 8.4M/day to opex.
> MGM Resorts International could be losing between $4.2 million and $8.4 million in daily revenue
It would be silly to correct someone who said "I just accepted a $120,000/yr job" with "you don't really know for sure, you could get fired or die". The colloquial presumption is that the rate of future income cited is dependent on a steady trajectory without confounding variables.
About as real as money.
I also wonder how much pressure it puts on MGM - who are no doubt very much aware of the loss (every major outage I've been on eventually comes down to how much did this cost us - whether it's money, customer attrition, customer trust etc) vs how much pressure it puts on executives following along to maybe pay attention to their IT and security teams. Pipe dream.
What the difference between not earning $8M and earning $8M and losing it?
Bank account looks pretty similar.
Not the same think as avoiding shopping somewhere.
There is a difference between losing money (like someone is actually stealing the money) and not getting money you were hoping/expecting to get. In this context it can even be a little bit confusing since there are criminals involved that could actually be stealing money.
Language has lots of ambiguities and despite this being a common way of describing this situation, I don't like it. Some people don't like the word "moist" either and that's just fine. It's an opinion.
After all, it only applies to future payroll periods.
A slightly more misleading use of "losing money" is for example when movie or music companies claim they are "losing" billions of dollars to piracy, when there is no reason to believe that every pirated copy would instead be purchased at full price, if only piracy were eliminated.
Equipment, man hours, botched projects, and lawsuits are going to push that number waaay higher, and even then I feel like it's got to be pretty low given the vast amount of money that passes through every day. On a 15% hold 42 million would work out to 280 billion of flow through the slots max (and obviously that's estimating high and assuming all revenue is from slots).
So 8 million a day is $53 billion in coin in that's not occurring? Maybe that's correct.
Doing quick napkin math so pardon any errors.
You can't let the scammers dictate what a casino does, MGM is already in the business of scamming people. They'll build their whole system from the ground up and be incredibly resistant to future attacks.
This mania to "integrate everything" is dangerous.
If it's war, elevate your game. (business opportunity?)
Fixed
"[Okta] is one of the things that I can put in my toolkit to say, ‘Hey, we're gonna move faster because we have this identity component nailed.
Scott Howitt, CISO, MGM Resorts International"
That's a testimony from Okta's website.
https://investors.mgmresorts.com/investors/news-releases/pre...