[HN Gopher] MGM is down, cybersecurity attack ongoing
___________________________________________________________________
MGM is down, cybersecurity attack ongoing
Author : codex_irl
Score : 87 points
Date : 2023-09-11 17:44 UTC (4 hours ago)
(HTM) web link (www.casino.org)
(TXT) w3m dump (www.casino.org)
| tunnuz wrote:
| Makes me think of the Sony hack by the Lazarus Group.
| nosmokewhereiam wrote:
| Allegedly due to the release of a movie. I'd assume this MGM
| resort is extortion/DOS.
|
| ...which doesn't eliminate them. Recent visits and timing would
| be impeccable.
|
| Every day they are down is $$$$$$
| tpmx wrote:
| I'm currently rewatching the Las Vegas (2003) NBC TV series (the
| one with James Caan, Josh Duhamel, James Lesure, Molly Sims,
| Nikki Cox, Vanessa Marcil etc). Feels on-brand; like every second
| ep is about some fantastic heist.
|
| It's worth rewatching as a guilty pleasure, IMO. Feels quite
| alien compared to current fare. It's dumb but well-crafted, fun
| and glitzy and never takes itself too seriously. I miss that kind
| of show.
|
| Surprisingly high production values for the time. It's available
| in 1080p with decent quality, somehow.
| plasticsoprano wrote:
| Ed Deline would never allow such as thing. Mike would most
| certainly be on it.
| codex_irl wrote:
| Related discussion
| https://www.reddit.com/r/vegas/comments/16fz1d3/mgm_has_been...
| RyanAdamas wrote:
| Does somebody have a magnetron?
| Animats wrote:
| Almost all news available is an echo of the press release. Not
| much real info.
| karaterobot wrote:
| The linked article is down, here's an archive
| https://web.archive.org/web/20230911174437/https://www.casin...
|
| Though the article itself says details are scant, so it's just
| going to be speculation. I'd love to know what happened though.
| abathur wrote:
| Take w/ requisite salt, but per Daily Mail [1]:
|
| > Thousands of guests at MGM Resorts in the Las Vegas strip have
| been locked out of their hotel rooms after the company was hit
| with a cyber attack, according to reports.
|
| > MGM Resorts International has about 48,000 rooms on The Strip.
| The company's properties include Mandalay Bay, the Bellagio,
| Luxor and MGM Grand, among others.
|
| > The outage, first detected on Sunday night, has affected
| company emails, reservations, booking, room keys and casino slot
| machines.
|
| [1]: https://www.dailymail.co.uk/news/article-12505921/MGM-
| Resort...
| spdustin wrote:
| That story literally copied/pasted from 8NewsNow [0]
|
| [0]: https://www.8newsnow.com/news/local-news/mgm-resorts-
| release...
| AlotOfReading wrote:
| They almost certainly got the story from the same wire
| service rather than copying from each other.
| lainga wrote:
| How do those hotel door locks work? When I had an apartment
| with a tap keyfob, it was battery-operated and the fob seemed
| to be programmed for that specific lock, so I thought they
| could work offline.
| alwaysrunning wrote:
| I did a project several years ago for mgm that involved BT,
| player cards, key systems, wifi, etc and I can confirm they
| hotel locks are controlled centrally for various reasons.
| wombat-man wrote:
| Yours is probably meant to work indefinitely. I guess hotels
| look at the card id and see if you have access at that
| moment.
| _joel wrote:
| Apartment? I assume your home? The upkeep of locks in a hotel
| is a bit more involved, as customers lose keys and they need
| to be reset for the next room guest (for larger hotels, at
| least)
| glitchc wrote:
| In a modern hotel with tap cards, all the locks are wired to
| a central system.
| caol wrote:
| MGM hotel rooms can be unlocked with smartphone NFC tap. You
| don't even need to visit the front desk to check in, just log
| in to the app. But if you can't open the app you can't get in
| your room. I'm guessing the front desk can issue keys to a
| guest in the event they lost their phone or something, but if
| the network is down for the front desk too then they might
| not be able to issue keys.
| bee_rider wrote:
| We often make fun of IOT and unnecessary app stuff, but
| these features 1000% make sense.
| napoleongl wrote:
| These days the locks are online so that you can block a lost
| keycard from the front desk. Previously you had to open the
| lock with a never keycard than the lost one to make the lost
| one inoperable. That works kinda fine in a small hotel but
| not when you 48000 rooms with millionaires in them.
| foota wrote:
| Fwiw you could probably build this in a way that it
| continues to operate without internet. This creates a new
| attack vector (disable the internet and you can't revoke
| access) but that's probably acceptable given the physical
| attacks possible.
| amenghra wrote:
| Each key gets a revision number. When the first set of
| keys are created, they get revision number 0. The lock
| records a high water mark of the revision numbers it has
| seen. Only keys matching the water mark get to unlock the
| door.
|
| When you want to revoke a key, you re-issue a new set
| with a higher revision number. When the guest checks out,
| you issue the next revision number to the next guest,
| effectively disabling the previous set.
|
| You do all this as a fallback when the network fails.
| This way, you can still disable keys in real-time when
| people checkout of their room.
| netsharc wrote:
| Ocean's 0x11? I wonder if it's just an attack against their email
| servers or a bigger one, how networked are their operations? If
| we believe the urban legends about how casinos operate, there's
| probably interesting conversations a cyber-attacker could find.
| lucisferre wrote:
| I think you meant 0x0B.
| _joel wrote:
| beat me to it, unless I've missed a few movies since!
| petemir wrote:
| Actually it would be 0x0E, 0x0B, 0x0C, and 0x0D already
| happened.
| mixdup wrote:
| almost certainly just a random/typical ransomware attack, not a
| specific target at them because they're a casino
| jjkaczor wrote:
| Very networked - but their email servers are now likely cloud-
| based SaaS.
| mickdarling wrote:
| I was disturbed to hear from people first hand in Vegas saying
| it was making the ATMs inoperable. No details on how
| inoperable, like if it is just certain banking features or
| everything. The ATMs should not be effected in the same kind of
| attack that would take down the website and booking systems.
| Those should all be separate.
| IAmGraydon wrote:
| It's entirely possible that these systems were hacked
| separately.
| dboreham wrote:
| Possibly the ATMs get network connectivity via a path that
| has either been affected by the attack directly or shut down
| as a precaution.
| wintogreen74 wrote:
| I don't believe these are typical bank ATMs but specific to
| MGM that manage all the casino games (ex: pay-outs,
| loyalty, etc) as well, so would be tied into any MGM
| systems.
| plasticsoprano wrote:
| Casino floor ATMs aren't just ATMs. They are also ticket
| redemption machines and therefore have to connect to the MGM
| network to redeem. I'd imagine the whole machine shutdown for
| security reasons if network connection is lost.
| mickdarling wrote:
| Yes, I think that MGM has actively shut everything down,
| rather than some massive hack that has effected all these
| separate systems.
|
| Best guess is that with the F1 races coming soon with what
| is expected to be the largest cashflow through Vegas ever,
| that MGM Resorts IT found issues in an audit in preparation
| for that massive event, found anomalies, and pulled the rip
| cord to shut everything down till they could sort out what
| systems were actually hit.
|
| That is materially different than a massive hack effecting
| all these various systems though.
| plasticsoprano wrote:
| MGM has acknowledged it's an attack [1] and certain vegas
| gossip sites have stated that Caesars was hit last hit
| last week but was able to keep it better under wraps.
|
| 1. https://www.reviewjournal.com/business/casinos-
| gaming/mgm-re...
| mickdarling wrote:
| Right, they say almost exactly what I said above.
|
| "MGM Resorts recently identified a cybersecurity issue
| affecting some of the Company's systems. Promptly after
| detecting the issue, we quickly began an investigation
| with assistance from leading external cybersecurity
| experts,"
|
| "We also notified law enforcement and took prompt action
| to protect our systems and data, including shutting down
| certain systems."
|
| The systems are down due to MGM shutting them down, not
| the active attack shutting things down.
| imglorp wrote:
| While there's something to be said for ransomware
| targeting casinos, "because that's where the money is,"
| that might also attract the wrong attention, and not all
| from the government. They might wish it was only from the
| government.
|
| https://www.politico.com/news/2022/01/14/russia-colonial-
| pip...
| bsimpson wrote:
| Title should be "MGM Resorts Suffers Cybersecurity Attack, System
| Outage" (following HN norms), or at least include "Resorts." MGM
| Resorts was spun out of the movie studio in like the 70s.
| sschueller wrote:
| Agreed, I thought it had something to do with the on going
| actors and writers guilds strike.
| dylan604 wrote:
| I thought maybe it was hacking to get content. So at least
| the title instilled a bit of curiosity even if it wasn't the
| story I had imagined from just the headline
| bigbillheck wrote:
| If they're going to shut something down, better a casino than
| anywhere else.
___________________________________________________________________
(page generated 2023-09-11 22:01 UTC)