MGM expects $100M hit from hack that led to data breach
reuters.com
reuters.com
Rumor was that Caesars was hit by the same group, and paid the ransom.
As a reminder, these attacks are overwhelmingly carried out by Russian gangs, and are only possible because of crypto. See https://www.lawfaremedia.org/article/ransomware-problem-bitc... for more.
Marcus Hutchins: Why Destroying Bitcoin Wouldn't Stop Corporate Ransomware
I don't know if it would stop it, but without cryptocurrencies, it would certainly be much less. Laundering USD is significantly harder than laundering Bitcoin.
What exactly do you think people "launder" Bitcoin to? Why would it be harder to launder dirty USD than Bitcoin?
The end goal is the same, clean money you can use for any purpose. With USD, you only need to nestle it into a clean business that doesn't get scrutinized. Add in a step between with Bitcoin and suddenly it becomes harder.
I think the main issue is that with USD you need a dirty entry point that could compromise you at the moment of transfer, rather than with Bitcoin where you can chose the exit point whenever you want, and the entry is less risky. But still, adding Bitcoin to mix further complicates and adds risk to the overall process.
> without cryptocurrencies, it would certainly be much less
Isn't the (estimated) USD black market without cryptocurrencies vastly bigger than the black market of Bitcoin already, has been since forever and seems to continue to be like this for the foreseeable future?
Of course you can do the same thing with USD by using cash. A package of cash mailed to a fake address (where your courier receives the package from the mailman) is as untraceable as anything you can do with crypto. It is however more effort and potential risk.
"Transferring USD to a hostile nation is significantly harder than transferring Bitcoin. Crypto's ratio of criminal to legitimate use-cases is tiny compared to USD, and continues to shrink."
The initial claim was "Laundering USD is significantly harder than laundering Bitcoin", not about transferring currency between two countries.
Your rebuttal, while pedantically correct, does not refute their larger point that Bitcoin greatly aids ransomware.
Furthermore, I'd argue it is easier for ransomware groups to transfer large values of illicitly-gained Bitcoin across borders without the possibility of interception by authorities. This is a key step in international money laundering.
It's actually a great filter: it makes sure that people are already financially committed and keeps away tourists that don't want to spend.
From my point of view I rag on crypto because I’ve yet to see it produce any real world value outside of scams, frauds, and illegal activity.
Traditional finance is slow and cautious on purpose. Having to deal with each country’s laws, regulations, and individual sovereignty is very much a real thing. A platform like venmo could do instantaneous cross border payments today if it were only a technical problem. But it’s not. It’s a human problem that arises from countries governing themselves with their own banking and finance laws.
Now, if your argument is that we should ditch countries sovereignty and ignore laws to make finance quicker, easier, and more private; then that’s argument I can understand. I don’t agree with that argument at all, but if that’s an opinion of someone I can see why an anarchistic point of view could resonate.
How many burritos did you get at 7/11 via BTC payments? I bought a car during COVID -- there weren't any places for me to pay for it with BTC. My mom didn't, and won't, use it for anything.
That like 5 dudes in San Fran bought or sold a house with it is really just exceptions proving the rule.
Are you taking the view that all laws are just? If not, then you must admit that crypto has some value where it helps to route around unjust laws (e.g. many people on this site consider the war on drugs unjust and ineffective).
IMO it's absolutely not a valid path forward to have citizens selectively choose to ignore/evade certain laws that they personally deem unjust
Crypto is a joke in search of a problem that has attracted a cult of personality ("obviously detractors are just the US government!")
In its entire lifespan the uses of crypto (by and large) I've seen went something like
- Curiosity for edge-case nerds
- Buying drugs on Silk Road
- HOLY SHIT I SHOULD PUT MY RETIREMENT IN THIS I'LL BE A BILLIONAIRE!
- Buying ugly monkey jpegs
This is ignoring all the absolutely monumental abuse of the entire sphere it generated and just trying to name the major "uses" over the last decade-plus
- getting fleeced, and watching the exchanges burn down or get indicted
x = ["languages", "alphabets", "keyboards", "electricity", "computers", "linux/windows", "internet", "crypto"]
I have the suspicion that we'll be blaming AI soon.
Besides, while crypto is definitely useful, the financial system seems to work fine too.
"U.S. banks and financial institutions processed roughly $1.2 billion in likely ransomware payments in 2021"
https://www.cnbc.com/2022/11/01/us-banks-process-roughly-1po...
You can't use USD bank transfers (you open yourself up to SEC and DoJ prosecution), you can't use gold (the logistics are near impossible), and you can't transfer assets (same story as above).
Crypto is unique in that it's both a virtual store of assets, and has infrastructure that can exist independent of western financial infrastructure
These scams are all still incredibly profitable despite relying entirely on the regular financial system. There is no reason to think ransomware would stop in the absence of cryptocurrency given that extensive infrastructure has existed and currently exists to "cashout" proceeds of fraud. And in the ransomware case it's even easier because the victim is willingly making the payment, and the attacker can just not give the decryption key if the victim trys to stop the payment in any way.
And yes, this scales. If you ever looked at the promoted stories on Snapchat a few years ago, you may have seen a user with the name "The Billionaire Gucci Master" living a very opulent lifestyle. That was all paid for with business email compromise money.
"In 2012, U.S. federal regulators hit HSBC Holdings with a $1.9 billion fine, along with $665 million in civil penalties, for significant lapses in its compliance and anti-money laundering (AML) systems. HSBC laundered over $881 million for Mexico's Sinaloa and Colombia's Norte del Valle drug cartels."
It provides no real benefit it and is a net negative to humanity imho
Wouldn't most Russians need money in Russia? What am I missing?
1. It is generally viewed as safer to keep large amounts of money outside of Russia. This is both because the Russian economy is bad, and because organized crime is a huge problem inside of Russia.
2. Russia and Russians have large shortages of things that can easily be bought outside of Russia. Once bought, they are fairly easy to smuggle back into Russia. But first you need to have money outside of Russia.
3. Russians like vacations. Getting yourself out of the country is easier than getting your money out of the country.
> Besides, while crypto is definitely useful, the financial system seems to work fine too.
What percentage of those payments was someone who had never purchased crypto before buying it to make a ransomware payment in crypto?
In a lot of cases, it is an unexpected purchase of crypto.
Remember, large payments generally start and end in the financial system. The interesting bit is what is in the middle to make it hard for law enforcement to track down and stop crime.
Yeah, it's a bummer the perfect/no crime world we lived in pre-crypto got ruined by crypto. /sarcasm
I want to pick on this, because its both true and untrue, depending on how far back you look at this illegitimate business. Ransoms did not use crypto at first, but they are now the de facto payment. Antiquated ransom payment via gift cards, MoneyPak, Western Union, etc. are all still viable options for gangs.
The current scale and profitability is based on hitting companies for large amounts of money. And that very much depends on crypto.
Perhaps they were first figured out because of crypto, but now that the genie is out of the bottle they can't be regulated away. They'll continue to be possible even if the government of a victim nation cracks down on Bitcoin.
As long as:
1. Computers are complicated, it will be possible to trick users into running software that does things they don't want, and
2. Factoring numbers is harder than multiplying numbers, it will be possible to use asymmetric cryptography to encrypt those files, and
3. Money can be sent across international borders, because rich countries want to buy cheap stuff from poor countries, and
4. Jurisdiction ends at national borders, so Russian gangs won't get prosecuted for receiving money from American/European victims,
ransomware will continue.
Sure, Viagra spam stopped working when credit card companies cracked down because while someone will send $100 over a credit card in the privacy of their home, if you make it too difficult they're going to give up.
But the corporate ransomware model doesn't cease to work if instead of having your negotiation team turn the corporation's cash into Bitcoins they instead have to go to Western Union and turn it into rubles. We're talking about a $100M transaction, heck, you could charter a plane to Russia and it would be a rounding error in the end.
Do you seriously think that:
A. Any western union on the planet keeps $10m cash on hand or even 10% of that?
B. The US would even allow western union to participate?
Crypto is absolutely a requirement for this racket to work.
I'm personally waiting for the first public reports of criminal gangs using Chat GPT to automate spear phishing at scale.
I'm sure it is happening already, but the victims are keeping it quiet. The use case is too obvious. Identify key people in an organization from the website, Linked In, etc. Find them on social media. Find their less technical friends. Compromise the friends' accounts in various ways. Then send targeted phishing attacks to your real target. With every step of this automated by LLMs.
When you're requesting millions from a target the payment method becomes fungible; do you think MGM has a million bitcoin to give? No they go out and spend cash to get the bitcoin and then give it. If the attackers requested diamonds then instead you'd have to go out and buy diamonds and then give them.
Cutting off credit cards worked because the payment method was not fungible. If they didn't accept CC then they're not getting orders.
They might... do they accept bitcoin at their casinos or online gambling sites?
A million dollars worth of bitcoin? Probably, and even if they didn't it would be trivial for them to get.
Payment networks are obviously not an option. Visa and her peers are not going to deliver the funds.
The only thing left is crypto. In fact it is the only use case where crypto is the preferable solution. I'll quote Stephen Diehl: "Any application that could be done on a blockchain could be better done on a centralized database. Except crime." [https://www.stephendiehl.com/blog/nothing-burger.html]
Also, the first paragraph of your first link (the Wikipedia page for "Ransomwware") literally ends with "... and difficult to trace digital currencies such as paysafecard or Bitcoin and other cryptocurrencies are used for the ransoms, making tracing and prosecuting the perpetrators difficult." Crypto and ransomware are absolutely intertwined in 2023, and have been for well over a decade.
Well not Steve Wynn personally but I mean how do you think the Somali pirates got paid? They literally airlifted them cash. USA does the same thing with Iran as well ...
When you get into the millions spending a dozen thousands on transaction fees is worth it if the transaction otherwise wouldn't occur. Removing BitCoin probably will reduce something like Petya which only wanted ~$300 but it absolutely will not stop MGM or hospitals from being attacked for millions.
> Payment networks are obviously not an option. Visa and her peers are not going to deliver the funds.
SWIFT will absolutely transfer the funds; social engineering to receive wires you're not supposed to is a lucrative crime (i.e. "CEO Wire Fraud"). VISA probably just won't because they'll find a transaction of that much with no collateral as a huge risk.
> Also, the first paragraph of your first link (the Wikipedia page for "Ransomwware") literally ends with "... and difficult to trace digital currencies such as paysafecard or Bitcoin and other cryptocurrencies are used for the ransoms, making tracing and prosecuting the perpetrators difficult.
I'd rather trace a difficult to track currency with a public ledger (BitCoin) than an impossible to track currency without a public ledger (USD).
> Well not Steve Wynn personally but I mean how do you think the Somali pirates got paid? They literally airlifted them cash. Again, cash is not an option for the scale of the operation that modern ransomware represents. According to a United Nations-backed report, Somali pirates made between $339 million and $413 million in ransom profits between 2005 and 2012. The highest ransom on record was $13.5 million, paid in April 2011. It should be noted that in 2011, Bitcoin's price rose to $32 on June 8, but then plummeted to $0.01 within a few days. The price of Bitcoin peaked at $30 in June 2011, but then dropped to $5. Bitcoin finished the year at $4.70. Not exactly a viable alternative at that time. Now compare those 8 years to any recent year's ransomware take. "Total ransomware revenue fell to at least $456.8 million in 2022, down nearly 40% from the $765.6 million extracted from victims in 2021."
But ok, back to the present: are you suggesting that a US company would/should/could just charter a flight into Russia? That everyone, including the US and Russian government, knows has millions of dollars of cash sitting on-board? And you think this wouldn't hit any snags? If you have an above board way to solve this then there are a number of cartels would love to hire you. Hell, not even the ransomware gangs would be comfortable with this arrangement, as bigger crime syndicates with better connections to the Russian state would be all but guaranteed to intercept the flight. And good luck getting the US government's blessing to send cash into a place like North Korea, who is very active in the ransomware space.
> SWIFT will absolutely transfer the funds; social engineering to receive wires you're not supposed to is a lucrative crime (i.e. "CEO Wire Fraud"). Does SWIFT accept applications from known ransomware gangs? What about accepting applications from fly-by-night operations located in former Soviet states with no institutional history? Don't be ridiculous.
And how does stealing funds being sent to someone else help you when you are trying to get funds sent directly to you? Are you suggesting that MGM would collude with the ransomware gangs to send funds via SWIFT to a 3rd party, such that the gang would be expected to intercept them thus satisfying the ransom? Or are you suggesting that SWIFT would knowingly transfer money intended for cybercriminals to some 3rd party, with the expectation that the gang would intercept the funds? This is just getting silly.
> VISA probably just won't because they'll find a transaction of that much with no collateral as a huge risk. Visa won't because they aren't going to risk their business with functioning governments to collect some transaction fees to do work for known criminals doing public crime.
> I'd rather trace a difficult to track currency with a public ledger (BitCoin) than an impossible to track currency without a public ledger (USD). Not sure what the point of this statement is, except that it seems to buttress the text you didn't copy, namely "Crypto and ransomware are absolutely intertwined in 2023, and have been for well over a decade", which is about as non-controversial as they come. As an aside though, plenty of organizations actually have a lot of success tracking that "impossible to track currency without a public ledger (USD)". In fact, here is some information about tracking the cash given to Somali pirates: https://www.cnn.com/2013/11/02/world/africa/horn-of-africa-p...
Cheers.
Parachute:
> >TME: Can you tell us about how you would arrange for ransom deliveries?
> We developed a special mechanism that allowed us to drop the ransom out of an aircraft by parachute. The pirates would collect the money after it fell into the water, take it to the ship, count it and then leave. At that point another team that we had already pre-positioned would board the ship, cross load supplies, help the crew get it underway again and escort it to the nearest safe port.
* https://maritime-executive.com/editorials/q-a-with-rob-phayr...
Once that's done you'd probably go to the 'standard' techniques that (e.g.) drug lords would use with cash. Assuming it wasn't spent on hookers and blow:
* https://www.cnn.com/2013/11/02/world/africa/horn-of-africa-p...
This is not even remotely true. Crypto is definitely the best licit way to move value around the world, so sure, it also is the best way to move illicit value around the world. But look at any Illicit Financial Flows report [1] and you will see that crypto is still marginal.
AFAIK Caesars customers were never exploited after the fact. On Twitter I'm hearing MGM Sports Betting app customers are getting drained right now.
But if you follow the trail, Scattered Spider had the hard ransomware work done by ALPHAV, also known as Black Cat, https://en.wikipedia.org/wiki/BlackCat_(cyber_gang). And THEIR developers and money launderers are linked to DarkSide, https://en.wikipedia.org/wiki/DarkSide_(hacker_group). Which is based in Russia.
So basically a bunch of young Western men participated in the social engineering. But the real computer knowhow and methods of getting paid trace right back to Russian criminals who are willing to work with them.
> the incident had disrupted portions of the company's IT infrastructure... The company expects a loss per share of between 35 cents and 75 cents in the quarter ended on Sept. 30, and for net sales to fall by 23% to 28% from a year earlier. It had reported profit of 68 cents per share in the year-ago period.
Still, you see CISOs fight tooth and nail to get a couple million approved for boosting cybersecurity posture.
https://www.reuters.com/business/retail-consumer/clorox-expe...
EDIT: @RugnirViking, my brother in christ, I agree with everything you said about culture.
Aren't they pretty good at financial risk? isnt that like their only job a lot of the time?
Idk it seems to me it must be possible to make a good argument for this stuff - How do cybersecurity consulting firms pitch to clients? Could McKinsey etc get in on it?
It's just hard internally because a lot of the time it requires the culture to have been there from the beginning. Changing the culture if it's not present already is like trying turning a supertanker with a desk fan. People resent loss of freedoms, and operational restrictions prevent getting everyone to understand the whys
That's a pretty mild impact. Multiply that with the low probability of this actually happening to a given company, and taking the risk doesn't sound sooo bad. Obviously it went wrong in this case, but it's hard to tell from the outside if that's because they did bad risk management or because they got unlucky on a calculated risk.
There’s always a balance of risk and the cost of mitigating risk.
One way to mitigate risk is simply buying an insurance policy which in many cases may be cheaper than paying a security firm to protect yourself proactively.
Cyber insurance often includes things like coverage for a PR firm to help regain as much reputational damage that may have been incurred.
Many cyber insurance plans also includes coverage for paying ransoms.
(I’m playing devils advocate somewhat, buying insurance to protect against cyber is something companies should do alongside of taking a proactive approach to securing systems)
https://news.bloomberglaw.com/insurance/as-cyber-insurance-d...
(I have also provided comments to the US Treasury on backstopping cyberinsurance and perverse incentives around doing so)
To a certain extent insurance shouldn’t need to verify controls if they’re able to have a company fill a questionnaire, and if their answers aren’t accurate the insurance carrier can use that as a basis for denying the claim.
I would hope any federal program (if one comes about) works similarly. “We will only cover incidents if we can verify after the fact that you had these controls and mitigation measures in place prior to the attack”
> I would hope any federal program (if one comes about) works similarly. “We will only cover incidents if we can verify after the fact that you had these controls and mitigation measures in place prior to the attack”
Mostly the gist of my public comments. If you obtained cyber insurance under false pretenses, you not be getting federal dollars. But also, questionnaires alone are no longer sufficient (imho). Really want to prevent a repeat of FEMA. Incentives matter.
they couldn't complete some of those, and eventually just punted for lower levels of coverage. cost to meet their requirements exceeded the cost of the lower + coverage and expected loss. Cue the Fight Club recall scene.
Every single policy written 5 years ago is underwater and every single policy with a large coverage amount is so hilariously underwater that there is a good chance that they will ruin the insurer and all of their re-insurers. For instance, the courts recently ruled in favor of Merck for a 1.4 G$ claim due to the 2017 NotPetya cyberattack [1]. That alone was more than the premiums of the entire worldwide cybersecurity insurance industry in 2015 [2]. It is to the point where, from what I have heard recently, the cybersecurity insurance vendors have largely given up writing new policies with more than a few million dollars worth of coverage.
They want to stay in the business so they are ready when the risk landscape stabilizes, but profitable policies need the premiums to be tens to hundreds of times higher than the standard backward looking actuarial models would suggest. So, if your competitors are dumber than you are, they will give policies with ridiculously lower premiums, not realizing they are going to be bankrupt in a few years. The only way to write a competitive policy in that environment is to take a loss, but limit the coverage to bound the loss to something survivable. Then you hunker down until the risk landscape stabilizes and everybody writing dumb big policies dies allowing you to write new policies with correct, vastly higher, premiums.
[1] https://www.securityweek.com/court-rules-in-favor-of-merck-i...
[2] https://content.naic.org/sites/default/files/cmte-c-cyber-su...
Oh, but what about the banks? Yeah, those are the security executives who personally told me and my colleagues that when asked. They literally have 100 M$ budgets up to 1 G$ budgets and they said that. The problem is not money, the problem is that commercial IT security technology and vendors do not work against professional, financially-motivated threat actors.
I’m willing to bet that a place like MGM has utterly abysmal security. You don’t see regular attacks against top-tier companies because a lot of them invest a reasonable amount.
To use the Caesar Entertainment incident that happened just before as a example, they purportedly paid a 15 M$ ransom. Is raising the cost to attack them from 10 K$ to 1 M$ really going to stop someone from collecting the 15 M$ payday? Oh no, I will only make 14 M$ instead of 14.99 M$, no point in attacking them. No, that is ridiculous. Making it harder is not a solution, you need to make it unprofitable.
If it is profitable you will eventually be hit by a incident and that incident can be unboundedly bad all the way up to completely destroying your business. In addition, your susceptibility is not random. A targeted attack will succeed and will be wildly profitable to perform no matter what you do. This is not a "I need to outrun you, not the bear" scenario. The bear is very hungry and can catch both of you; it will eat the fatter and tastier one, not the slower one. Then it will catch and eat the other one. Your only protection is being less tasty so you get eaten last.
You need to make it unprofitable and no extant solution available today in commercial IT can make it unprofitable for financially-motivated professional attackers. "Best practices" are maybe 1-10% of the way to minimally adequate; we need solutions 10 to 100 times better than the current gold standard to get there. Yes, I said times, not percent. We need a 1,000% to 10,000% improvement to get to the minimum bar. Until then, buckle in since things are just getting started; we are in for some real wild times on this ride.
If you are considering for yourself, then there is the short term and long term view.
The short term view is that the cost of compromise is still low. As I said in a sibling comment, the cyberattack industry is still going through growing pains, so from a practical perspective, if you chart out the rate of cyberattack growth, you still have maybe 5-10 more years of coasting before things become a existential-threat sort of problem if you are running a big business. For instance, MGM made 14 G$ in revenue last year, 100 M$ is a pain, but not life threatening. With 5 more years of sophistication they can probably make that 1-3 G$ and then you are in for a real world of pain.
The long term view is to assume that every element of your system that is network connected is easily hacked. Then you need to redesign your system and processes around that assumption. All of the conveniences of network connectivity are going to be liabilities. With careful thought you can probably reorganize your systems around this assumption for a relatively modest impact to operations. This will not protect you per se, but it will make your business processes more robust. The usual thing you lose by minimizing system connectivity is that latency gets worse, but you can usually mitigate this with more batch processing. Your turnaround time gets worse, but your bandwidth stays the same. There are costs to redesigning your business processes like this, but they are a lot less than the hecklers claim since you will not use the exact same processes that assume low latency always-connected systems, you will change your processes to better suit the new normal. Unfortunately, I can not give you much more than a high level view here because it is very business specific.
If you are considering society, then the core problem is that the incentive structure is all messed up. Software deployment has no requirements on fitness for purpose and software companies can basically just lie about software security with total impunity are just two of the obvious problems.
Unlike basically every other industry, where your product has to nominally work, software basically has no expectation or requirement of working no matter the use case. You can use whatever crappy software you find to run a nuclear power plant and nobody bats a eye. That is ridiculous. Deploying software that is unfit for a use case should not be allowed. However, the definition of fitness depends on the use case and the criticality, no one size fits all set of requirements works. This is like how we have different standards for toys and bridges. This is how literally every other industry works. The EU Cyber Resilience Act supposedly has some of this, but I have not read it directly to comment on the specific implementation they did.
The other problem is that software companies are allowed to basically just lie about software security. Have you ever heard any company say anything other than "our product is secure" or "we have the most secure {X}"? These are meaningless terms. I propose that if you want to advertise security, you can say a dollar amount "our bank is secure against 15 M$ attacks", but then you need to put up a bug bounty for that amount. You want to lie and say 1 G$ when you know it is 10 M$, go ahead, you are going to lose your shirt. Also, to handle the consumer product angle you could divide the number by the number of devices or some fraction thereof. Yeah, 10 M$ might sound like a lot to a regular person, but if they can hack all 1 M of the units then they only need to get 10 $ per unit to make it worthwhile, so you really only have 10 $ of marginal security for your device.
I did not really directly answer your question though. If you really need to increase your security to the required level, then there is not much you can do. There is nothing currently available on the market that can do that and none of the current vendors is able to solve the problem. Basically anybody using the same old tired cybersecurity pitches is just selling you junk and anybody with a new spin on it is also probably junk. If you want real verification demand robust auditable test suites, unrestricted red team tests, formal specifications, and proofs of correctness. Those are basically impossible to fake and none of the clowns will be able to provide a semblance of those. Unfortunately, basically everybody is a clown, so all that will really happen is that you will find that there are no viable vendors.
Sorry I can not be of much help. The industry is a wasteland right now; we need to nurture solutions before we can use them.
I think the reality is more that most well prepared companies can be hacked, but that it takes a lot of resources, and that there are a number of companies with atrocious security that can be hacked with a moderate amount of effort.
Second of all, 1 M$ of hacking resources is like one or two person-years of skilled hacking labor. The counterfactual scenario you are considering appears to be tens of thousands of companies being hacked for 10 M$ per for a total of 100 G$ of revenue per year. Do you realize what you are expecting there? You wonder why 18 year old hacking nerds could not bootstrap a 100 billion dollar per year business (more than the estimated revenue of the entire illegal drug trade in the US and similar to the revenue of Facebook) with no venture capital and train and hire 10,000 skilled hackers (nearly a entire Google's worth of software developers) in under 10 years? Give them a break, 10 years after Facebook was founded they only made 12 G$/year and you are expecting some kids with no support structure to do 8x that while bootstrapping. For the world to look like your counterfactual, they would need 1,000% YoY growth for a entire decade; that is ludicrous.
I hope it is now clear that the reason everybody is not being hacked all the time is because there has not been enough time to grow into that yet. They are trying really hard though. Look at that report again. The mean ransom payment doubled from 2022 and the rate of high end payments quadrupled. In some other reports (that are behind signup walls), the number of attacks has been tripling YoY and the mean payment/ask has been tripling YoY for the past 5-10 years. That growth curve looks like a wall. The 18 year old hacker nerds who started these criminal enterprises 10 years ago are now 28 year old business people with 10 years of experience under their belt and have access to real organized crime support structures. This is why the attacks are growing so quickly, this is a greenfield opportunity that everybody is rushing to exploit as quickly as they can, but there are real limits to training talent and bootstrapping. Give them some time, we'll get there.
[1] https://assets.sophos.com/X24WTUEQ/at/c949g7693gsnjh9rb9gr8/...
"$100 an hour sounds like enough on this planet, yeah? Let's go with that, a nice round one hundred an hour!"
Job Description
Arganteal seeks an onsite Red Hat Linux System Admin "RHEL SysAdmin" in Las Vegas, Nevada for immediate work starting 9-21-2023. This role will be helping the MGM Grand Casino to build its net new IT environment after the recent ransomware hack.
Candidates must be willing to work everyday until the new IT environment is fully stood up.
We are open to people who will only work a grand total of 7 days!
Expected Dates of Service 9-21-2023 through 10-15-2023
Hourly Rate: $100.00 per on 1099
Location: Onsite at MGM HQ in Las Vegas (absolutely no remote work)
Visa Status: Must be US Citizen (no Green Cards or H1b visa candidates will be accepted)
Working Hours: Expect to work 10 hours per day 7 days a week
That's a contract worker? So what's gonna happen is this poor soul is going to build out some hacked-together junk as quickly as possible, get replaced, and the replacements will have no idea how anything works. Some time down the line, a server isn't going to get a critical update because nobody even knows it exists, and this will all repeat again once the hackers find it. :)
Just complete and utter trash.
The people running this casino don't seem all that bright. Unless that ad was a joke, in which case I guess I shouldn't be talking...
I see this type of message on so many statements about breaches. It seems like one of those things that can be said even when the potential usage in question would be extremely likely, because even if every marketplace for this stuff is advertising "identities stolen from MGM" for sale, that alone isn't "evidence" that it's actually what it says on the tin. If someone purchased it and showed their purchase to MGM, would that be sufficient "evidence" for them to not make such a statement?
MGM did about $13 billion in revenue last year and while things certainly sucked they were still making money while things were down. Slots weren’t running but table games were up and gaming isn’t the majority share of where they make their money. Room fees make more. Food and beverages make more. Entertainment makes slightly less than gaming. 100 million isn’t out of the question.
i runs a lot of casinos/hotels. But not MGM.