[HN Gopher] MGM is down, cybersecurity attack ongoing
       ___________________________________________________________________
        
       MGM is down, cybersecurity attack ongoing
        
       Author : codex_irl
       Score  : 87 points
       Date   : 2023-09-11 17:44 UTC (4 hours ago)
        
 (HTM) web link (www.casino.org)
 (TXT) w3m dump (www.casino.org)
        
       | tunnuz wrote:
       | Makes me think of the Sony hack by the Lazarus Group.
        
         | nosmokewhereiam wrote:
         | Allegedly due to the release of a movie. I'd assume this MGM
         | resort is extortion/DOS.
         | 
         | ...which doesn't eliminate them. Recent visits and timing would
         | be impeccable.
         | 
         | Every day they are down is $$$$$$
        
       | tpmx wrote:
       | I'm currently rewatching the Las Vegas (2003) NBC TV series (the
       | one with James Caan, Josh Duhamel, James Lesure, Molly Sims,
       | Nikki Cox, Vanessa Marcil etc). Feels on-brand; like every second
       | ep is about some fantastic heist.
       | 
       | It's worth rewatching as a guilty pleasure, IMO. Feels quite
       | alien compared to current fare. It's dumb but well-crafted, fun
       | and glitzy and never takes itself too seriously. I miss that kind
       | of show.
       | 
       | Surprisingly high production values for the time. It's available
       | in 1080p with decent quality, somehow.
        
         | plasticsoprano wrote:
         | Ed Deline would never allow such as thing. Mike would most
         | certainly be on it.
        
       | codex_irl wrote:
       | Related discussion
       | https://www.reddit.com/r/vegas/comments/16fz1d3/mgm_has_been...
        
       | RyanAdamas wrote:
       | Does somebody have a magnetron?
        
       | Animats wrote:
       | Almost all news available is an echo of the press release. Not
       | much real info.
        
       | karaterobot wrote:
       | The linked article is down, here's an archive
       | https://web.archive.org/web/20230911174437/https://www.casin...
       | 
       | Though the article itself says details are scant, so it's just
       | going to be speculation. I'd love to know what happened though.
        
       | abathur wrote:
       | Take w/ requisite salt, but per Daily Mail [1]:
       | 
       | > Thousands of guests at MGM Resorts in the Las Vegas strip have
       | been locked out of their hotel rooms after the company was hit
       | with a cyber attack, according to reports.
       | 
       | > MGM Resorts International has about 48,000 rooms on The Strip.
       | The company's properties include Mandalay Bay, the Bellagio,
       | Luxor and MGM Grand, among others.
       | 
       | > The outage, first detected on Sunday night, has affected
       | company emails, reservations, booking, room keys and casino slot
       | machines.
       | 
       | [1]: https://www.dailymail.co.uk/news/article-12505921/MGM-
       | Resort...
        
         | spdustin wrote:
         | That story literally copied/pasted from 8NewsNow [0]
         | 
         | [0]: https://www.8newsnow.com/news/local-news/mgm-resorts-
         | release...
        
           | AlotOfReading wrote:
           | They almost certainly got the story from the same wire
           | service rather than copying from each other.
        
         | lainga wrote:
         | How do those hotel door locks work? When I had an apartment
         | with a tap keyfob, it was battery-operated and the fob seemed
         | to be programmed for that specific lock, so I thought they
         | could work offline.
        
           | alwaysrunning wrote:
           | I did a project several years ago for mgm that involved BT,
           | player cards, key systems, wifi, etc and I can confirm they
           | hotel locks are controlled centrally for various reasons.
        
           | wombat-man wrote:
           | Yours is probably meant to work indefinitely. I guess hotels
           | look at the card id and see if you have access at that
           | moment.
        
           | _joel wrote:
           | Apartment? I assume your home? The upkeep of locks in a hotel
           | is a bit more involved, as customers lose keys and they need
           | to be reset for the next room guest (for larger hotels, at
           | least)
        
           | glitchc wrote:
           | In a modern hotel with tap cards, all the locks are wired to
           | a central system.
        
           | caol wrote:
           | MGM hotel rooms can be unlocked with smartphone NFC tap. You
           | don't even need to visit the front desk to check in, just log
           | in to the app. But if you can't open the app you can't get in
           | your room. I'm guessing the front desk can issue keys to a
           | guest in the event they lost their phone or something, but if
           | the network is down for the front desk too then they might
           | not be able to issue keys.
        
             | bee_rider wrote:
             | We often make fun of IOT and unnecessary app stuff, but
             | these features 1000% make sense.
        
           | napoleongl wrote:
           | These days the locks are online so that you can block a lost
           | keycard from the front desk. Previously you had to open the
           | lock with a never keycard than the lost one to make the lost
           | one inoperable. That works kinda fine in a small hotel but
           | not when you 48000 rooms with millionaires in them.
        
             | foota wrote:
             | Fwiw you could probably build this in a way that it
             | continues to operate without internet. This creates a new
             | attack vector (disable the internet and you can't revoke
             | access) but that's probably acceptable given the physical
             | attacks possible.
        
               | amenghra wrote:
               | Each key gets a revision number. When the first set of
               | keys are created, they get revision number 0. The lock
               | records a high water mark of the revision numbers it has
               | seen. Only keys matching the water mark get to unlock the
               | door.
               | 
               | When you want to revoke a key, you re-issue a new set
               | with a higher revision number. When the guest checks out,
               | you issue the next revision number to the next guest,
               | effectively disabling the previous set.
               | 
               | You do all this as a fallback when the network fails.
               | This way, you can still disable keys in real-time when
               | people checkout of their room.
        
       | netsharc wrote:
       | Ocean's 0x11? I wonder if it's just an attack against their email
       | servers or a bigger one, how networked are their operations? If
       | we believe the urban legends about how casinos operate, there's
       | probably interesting conversations a cyber-attacker could find.
        
         | lucisferre wrote:
         | I think you meant 0x0B.
        
           | _joel wrote:
           | beat me to it, unless I've missed a few movies since!
        
             | petemir wrote:
             | Actually it would be 0x0E, 0x0B, 0x0C, and 0x0D already
             | happened.
        
         | mixdup wrote:
         | almost certainly just a random/typical ransomware attack, not a
         | specific target at them because they're a casino
        
         | jjkaczor wrote:
         | Very networked - but their email servers are now likely cloud-
         | based SaaS.
        
         | mickdarling wrote:
         | I was disturbed to hear from people first hand in Vegas saying
         | it was making the ATMs inoperable. No details on how
         | inoperable, like if it is just certain banking features or
         | everything. The ATMs should not be effected in the same kind of
         | attack that would take down the website and booking systems.
         | Those should all be separate.
        
           | IAmGraydon wrote:
           | It's entirely possible that these systems were hacked
           | separately.
        
           | dboreham wrote:
           | Possibly the ATMs get network connectivity via a path that
           | has either been affected by the attack directly or shut down
           | as a precaution.
        
             | wintogreen74 wrote:
             | I don't believe these are typical bank ATMs but specific to
             | MGM that manage all the casino games (ex: pay-outs,
             | loyalty, etc) as well, so would be tied into any MGM
             | systems.
        
           | plasticsoprano wrote:
           | Casino floor ATMs aren't just ATMs. They are also ticket
           | redemption machines and therefore have to connect to the MGM
           | network to redeem. I'd imagine the whole machine shutdown for
           | security reasons if network connection is lost.
        
             | mickdarling wrote:
             | Yes, I think that MGM has actively shut everything down,
             | rather than some massive hack that has effected all these
             | separate systems.
             | 
             | Best guess is that with the F1 races coming soon with what
             | is expected to be the largest cashflow through Vegas ever,
             | that MGM Resorts IT found issues in an audit in preparation
             | for that massive event, found anomalies, and pulled the rip
             | cord to shut everything down till they could sort out what
             | systems were actually hit.
             | 
             | That is materially different than a massive hack effecting
             | all these various systems though.
        
               | plasticsoprano wrote:
               | MGM has acknowledged it's an attack [1] and certain vegas
               | gossip sites have stated that Caesars was hit last hit
               | last week but was able to keep it better under wraps.
               | 
               | 1. https://www.reviewjournal.com/business/casinos-
               | gaming/mgm-re...
        
               | mickdarling wrote:
               | Right, they say almost exactly what I said above.
               | 
               | "MGM Resorts recently identified a cybersecurity issue
               | affecting some of the Company's systems. Promptly after
               | detecting the issue, we quickly began an investigation
               | with assistance from leading external cybersecurity
               | experts,"
               | 
               | "We also notified law enforcement and took prompt action
               | to protect our systems and data, including shutting down
               | certain systems."
               | 
               | The systems are down due to MGM shutting them down, not
               | the active attack shutting things down.
        
               | imglorp wrote:
               | While there's something to be said for ransomware
               | targeting casinos, "because that's where the money is,"
               | that might also attract the wrong attention, and not all
               | from the government. They might wish it was only from the
               | government.
               | 
               | https://www.politico.com/news/2022/01/14/russia-colonial-
               | pip...
        
       | bsimpson wrote:
       | Title should be "MGM Resorts Suffers Cybersecurity Attack, System
       | Outage" (following HN norms), or at least include "Resorts." MGM
       | Resorts was spun out of the movie studio in like the 70s.
        
         | sschueller wrote:
         | Agreed, I thought it had something to do with the on going
         | actors and writers guilds strike.
        
           | dylan604 wrote:
           | I thought maybe it was hacking to get content. So at least
           | the title instilled a bit of curiosity even if it wasn't the
           | story I had imagined from just the headline
        
       | bigbillheck wrote:
       | If they're going to shut something down, better a casino than
       | anywhere else.
        
       ___________________________________________________________________
       (page generated 2023-09-11 22:01 UTC)