[HN Gopher] MGM losing up to $8.4M a day due to cyberattack, ana...
___________________________________________________________________
MGM losing up to $8.4M a day due to cyberattack, analyist says
Author : gmays
Score : 111 points
Date : 2023-09-19 16:39 UTC (6 hours ago)
(HTM) web link (www.reviewjournal.com)
(TXT) w3m dump (www.reviewjournal.com)
| justsomehnguy wrote:
| > MGM is not earning up to $8.4M a day due not spending $333.3k a
| day for a proper measures against cyberattack, analyist says
|
| Fixed
| zephyrus76 wrote:
| This really feels like 1650's nautical piracy. Someone outside
| the reach of the law of the targeted country's merchants, making
| tons of money by theft and ransom. And like the pirates of old,
| often supported by the host nation so long as their attacks
| disrupt the activities of rivals nations' merchants.
| willis936 wrote:
| Merchants provide a value to society and pirates harm that. The
| thieves are providing a value to society in this case by
| damaging casinos, which provide no value to society and only
| harm citizens.
| dfxm12 wrote:
| More than casinos are being damaged. There's also hotels,
| restaurants, etc.
| kube-system wrote:
| Casinos provide leisure and entertainment. If what you're
| actually trying to say is that they are overall a net harm,
| then I'd point out that imperial mercantilism was also quite
| harmful to many people. At least MGM hasn't overthrown any
| countries.
| mrguyorama wrote:
| In exactly the same way a heroin dealer provides leisure
| and entertainment. Selling access to an inherently
| addictive substance should not be a for profit endeavor.
| The incentives are inherently biased towards harming people
| for profit.
| kube-system wrote:
| You say this as if "addictive" and "harmful" are boolean
| concepts. These concepts have a wide spectrum in reality.
| People die every day from addictions to all kinds of
| socially acceptable products and services, whether it be
| the dopamine rush from an unhealthy or dangerous
| activity, a buzz from their favorite beverage, or the
| sugar rush from an unhealthy snack.
| willis936 wrote:
| I encourage you to walk through some casinos and take
| stock of what you see. The scales of enrichment and
| addiction are nowhere near the balance of candy and soda.
| paulddraper wrote:
| Depends on what the merchant is selling, I reckon.
| nosmokewhereiam wrote:
| Cyber privateering was mentioned like 10-12 years ago. Someone
| had a blog or similar referring to the 'Morgan doctrine'.
|
| Edit: I found it. It looks more professionally edited and
| lengthy than when I first came across it in 2010(!).
|
| Link: https://www.themorgandoctrine.com/2010/11/draft-01-cyber-
| pri...
|
| The Cyber Privateer Code (draft 02--updated on 6/28/2013): -
| Any unauthorized attempt to access your computer or phish your
| data access privileges constitutes a crime punishable by the
| looting of the attacker's assets by an authorized cyber
| privateer. All assets. Within 6 months of the attack.
|
| - If it is determined that the attacker is acting under
| explicit instructions from a larger organization or government,
| the assets of that organization or government are also forfeit
| to the extent that an authorized cyber privateer may confiscate
| them within a six month period of the original motivating
| attack. All assets.
|
| - The individual whose assets were seized by a cyber privateer
| --or the publicly and legally designated spokesperson for the
| organization or government whose assets were seized by the
| cyber privateer--has the "right of parley" with the head of the
| cyber privateering organization, such meeting to take place
| online in a two-way video conference, such conference to be
| publicly recorded by one or both parties and before the
| disposition of the booty but no later than 10 days from the
| confiscation.
|
| - Innocent victims whose assets are directly and mistakenly
| confiscated by cyber privateers (and whose funds are not
| returned within 10-days after the parley) shall be compensated
| in an amount equal to four times their loss, with interest
| accruing on the restitution amount at the rate of twelve
| percent per annum. This does not include victims of the cyber
| criminals, since they were already victimized.
|
| - Notifications and requests for parley must be unambiguously
| left by the cyber privateer so as to allow the right of parley
| to be exercised in a timely fashion.
|
| *These rules would of course lead to the worlds end in any
| significant conflict, imo. But it would certainly be fun for a
| minute.
| tpmx wrote:
| Many of us foresaw this (and _much_ worse) when we first
| heard about Bitcoin in 2009-2011. Yes, Bitcoin has its
| anonymity issues, but cryptocurrencies in general is what
| typically enables this kind of crime.
|
| Example:
|
| https://www.bloomberg.com/news/articles/2023-09-13/caesars-e.
| ..
|
| https://archive.ph/8BCDb
|
| _Caesars Entertainment Inc. paid tens of millions of dollars
| to hackers who broke into the company's systems in recent
| weeks and threatened to release the company's data, according
| to two people familiar with the matter._
|
| _Hacking gangs typically ask to be paid in cryptocurrency if
| they demand a ransom._
|
| I don't want to live in a world with 100% anonymous and
| untraceable payments.
| distortionfield wrote:
| > I don't want to live in a world with 100% anonymous and
| untraceable payments.
|
| Cash is equally as capable of this, though. The hackers in
| this situation could demand cash and practically nothing
| would change about the technical aspects of their attack.
| tpmx wrote:
| It's not.
|
| They would have to travel from e.g. Russia to Las Vegas
| to pick up the cash though. Or, I suppose, demand
| delivery of cash to Russia, or some other place.
| Whichever way, it's a lot easier for law enforcement.
| Suddenly a particular country is responsible.
| nico wrote:
| It never stopped, and the US is one of the worst offenders
|
| Check out War is a Racket, by US general Smedley Butler
|
| Also the Snowden documents and the whole Asange/Wikileaks case
| pphysch wrote:
| The "World's Policeman" thesis really fell flat.
|
| There is an urgent need to have effective international law-
| enforcement and justice.
| mcpackieh wrote:
| > _There is an urgent need to have effective international
| law-enforcement and justice._
|
| What makes you think any other organization given such
| privilege would do any better with it than the US? Even if
| they started out with good intentions, that kind of power
| will inevitably corrupt them.
|
| Embrace multipolarity. Benevolent, wise and just
| unipolarity will never happen.
| infamouscow wrote:
| Urgent to whom? We live in a multipolar world now.
|
| Countries already use criminals as political tools to
| advance their goals on the world stage. What makes you
| think expanding these efforts will somehow change existing
| geopolitical behavior?
|
| All systems of law break down into the imposers, and the
| imposed upon. You don't have to impose anything on the
| voluntarily compliant, but what about those that refuse?
| Are you going to invade or kill innocent people just
| because a few leaders don't want to play by your rules?
|
| Sanctions don't work for their intended political purpose.
| The only reason politicians talk about them is because it
| enables their corporate masters to swoop into markets and
| make a lot of money. (And if you disagree, I ask you find a
| study pointing to how sanctions were politically
| successful.)
| [deleted]
| readyplayernull wrote:
| Will we see machineguns and hacker hanging cages installed in
| their buildings?
| lainga wrote:
| God damn them all, I was told / we'd abuse the C's for American
| gold...
| zephyrus76 wrote:
| We'd file no bugs / thread no peers...
| [deleted]
| irtefa wrote:
| I'm curious if MGM fully understood their cyber risks. Many
| companies underestimate threats until something like this
| happens. After seeing MGM, if other hotels beef up security too
| (very likely), will overall costs for consumers go up?
| commandlinefan wrote:
| > underestimate threats until something like this happens
|
| And then, when it does, they blame the people who were pointing
| out the risks and suggesting solutions rather than the people
| who were ignoring those people the whole time.
| xfitm3 wrote:
| Security is a SG&A line item, I am sure they are far more
| fixated on physical security due to their business vertical and
| had a gap. There will be many cyber companies chomping at the
| bit to get a piece of the inevitable (I made this number up)
| 100m MGM will spend on Cybersecurity over the next 5 years.
|
| They won't make the same mistake twice and will build a
| comprehensive cybersecurity program, and it will succeed. Up
| until someone questions this cost and they forgot what they are
| paying for because everything was so smooth and repeat the
| cycle.
|
| The objective of security is risk identification and
| management, not creating an impervious barrier for potential
| adversaries.
| thefourthchime wrote:
| " They won't make the same mistake twice and will build a
| comprehensive cybersecurity program, and it will succeed. Up
| until someone questions this cost and they forgot what they
| are paying for because everything was so smooth and repeat
| the cycle."
|
| You couldn't have said it better.
| jarym wrote:
| > Many companies underestimate threats until something like
| this happens
|
| Speaking from my experience, many don't understand the threats
| even after an incident. The reaction is often to add 'more
| security' under any name. More restrictive policies, more
| scanning, more layers of MFA - just blindly layering on things
| because it's seen as 'more secure' without properly
| understanding how it affects risk is an awful approach to
| managing security.
| justin_oaks wrote:
| The goal is to make the boss feel more secure. And there are
| plenty of snake oil salesmen willing to sell to that boss.
| anotheruser13 wrote:
| And I would say T-Mobile not only doesn't understand the
| threats after their many data breaches, they have
| continuously failed to improve Cybersecurity.
|
| They have an incredibly crusty, buggy billing system written
| in PowerBuilder, and I swear it's a holdover from the Voice
| stream days
|
| Disclaimer: Worked there in Tech Support.
| raydiatian wrote:
| analyist
| bob1029 wrote:
| This is a good example of the kind of case study I will point to
| when someone starts to get cranky with my unyielding principle of
| putting the _entire_ business inside a single SQL database.
|
| When you have geo replicas and point-in-time restoration
| capabilities which can synchronously bring 100% of the business
| back from the dead in a matter of seconds/minutes...
|
| How many $8.4m days before a complete rewrite of all systems
| would be justified? If you are going to entertain a rewrite, why
| not use one system to rule them all so you can audit one thing
| and move on with life?
|
| This industry does not seem like a good fit for non-traditional
| technology stacks. I'd strongly consider putting my entire casino
| on a mainframe if I could. Any vendor who indicates a lack of
| willingness for integration with that tech stack would be
| instantly disqualified from selection. I feel like this is a
| really good technology bullshit filter for the kind of industry
| MGM is operating in. If it's not good enough for Visa or Amex,
| it's not good enough for a gambling operation.
| sentimentscan wrote:
| It seems like a bug/wrong infra, nothing that mainframe could
| fix. >it's not good enough for Visa or Amex, it's not good
| enough for a gambling operation. We have multicloud/kubernetes
| paulddraper wrote:
| What was their tech stack?
| insanitybit wrote:
| > Katz told investors in his Thursday and Sunday reports that
| damages from the cyberattack at MGM would be claimed against
| insurance, but it's unclear just how much would be covered.
|
| I'm curious to see how this plays out. After all, if MGM is
| audited and found to have been negligent, would insurance pay out
| at all?
| crazygringo wrote:
| Presumably the insurance requires a security audit (yearly?) in
| order to get in the first place?
|
| As long as the auditors OK'd it then the insurance should pay
| out. Unless they can show that MGM intentionally lied in the
| information they gave the auditors -- which will surely now be
| gone through with a fine-toothed comb.
|
| (See that HN thread from a couple of days ago wondering if they
| were personally liable for fraud for producing a document lying
| about pentesting.)
| insanitybit wrote:
| The audits you get for something like SOC2 are quite weak,
| I'm very curious to learn if the insurance team's audit is
| more thorough (if they perform one).
| Eji1700 wrote:
| I suspect that's just an initial breakdown. They're estimating
| 4.2 to 8.4 million a day out of the 42 million they normally
| make, but that's just on the revenue side.
|
| Equipment, man hours, botched projects, and lawsuits are going to
| push that number waaay higher, and even then I feel like it's got
| to be pretty low given the vast amount of money that passes
| through every day. On a 15% hold 42 million would work out to 280
| billion of flow through the slots max (and obviously that's
| estimating high and assuming all revenue is from slots).
|
| So 8 million a day is $53 billion in coin in that's not
| occurring? Maybe that's correct.
|
| Doing quick napkin math so pardon any errors.
| kneel wrote:
| MGM is smart for not paying.
|
| You can't let the scammers dictate what a casino does, MGM is
| already in the business of scamming people. They'll build their
| whole system from the ground up and be incredibly resistant to
| future attacks.
| whycome wrote:
| Gotta pay to play. What if the scammers told MGM they could
| play a game of chance to get their money back?
| anonymousiam wrote:
| I never like it when writers use the word "lose" to describe
| money not earned. Yeah, MGM is not earning as much as it could
| because of this attack. They are under pressure to settle with
| the attackers. Articles like this can increase that pressure. I'm
| glad that they aren't settling, and I'm certain that they will
| survive this attack.
| rahimnathwani wrote:
| If your employer gives you 2 weeks notice of employment
| termination, did you lose your job?
|
| After all, it only applies to future payroll periods.
| eddieroger wrote:
| Yes you lost your job, and will not receive money in the
| future. Money from a job is in exchange for services rendered
| to company. It's reasonable to say you can't lose something
| you haven't yet received, but it is also normal to say
| they're losing money given they had an incredibly high
| likelihood of actually receiving it.
| PopAlongKid wrote:
| The revenue may be going down, but that doesn't mean they have
| to operate at a loss (they could always cut their variable
| expenses to match the cut in revenue). It would be more
| accurate, but not as click-baity, to describe it as "MGM
| getting up to $8.4M less revenue a day".
|
| A slightly more misleading use of "losing money" is for example
| when movie or music companies claim they are "losing" billions
| of dollars to piracy, when there is no reason to believe that
| every pirated copy would instead be purchased at full price, if
| only piracy were eliminated.
| SoftTalker wrote:
| If your salary was cut 20% next year, would you think you were
| not losing money because you had not yet earned it?
| kube-system wrote:
| It's a loss of income. This is a common use of the word.
| bqmjjx0kac wrote:
| Well, it's a loss of projected income, which in many ways is
| not real.
| CamelCaseName wrote:
| It's not even that, it's revenue.
|
| > MGM Resorts International could be losing between $4.2
| million and $8.4 million in daily revenue
| kube-system wrote:
| Revenue _is_ a measure of income. Unless speaking about
| specific types of revenue or specific types of income,
| they are synonymous.
| hollerith wrote:
| Accounts don't think revenue and income are synomymous:
| income is revenue minus expenses. Now if you were to say
| that profit and income are synonymous, that I might be
| okay with.
| kube-system wrote:
| Revenue minus expenses is " _net_ income ". "income" is
| ambiguous.
| [deleted]
| kube-system wrote:
| It is just plain normal language to refer to a loss as a
| comparison against a current trajectory or current state.
| It is reasonable to assume that the reader/listener knows
| that the future cannot be predicted exactly, because this
| is generally true. This is why it isn't said explicitly.
|
| It would be silly to correct someone who said "I just
| accepted a $120,000/yr job" with "you don't really know for
| sure, you could get fired or die". The colloquial
| presumption is that the rate of future income cited is
| dependent on a steady trajectory without confounding
| variables.
| Groxx wrote:
| It's real enough that companies regularly borrow against
| it, which is about as real as anything is with money.
| JumpCrisscross wrote:
| > _it 's a loss of projected income, which in many ways is
| not real_
|
| About as real as money.
| paulddraper wrote:
| It's more real than not.
| libraryatnight wrote:
| There's lots of instances where I'd agree, but this one seems
| like a tried and true business with years of revenue to gauge
| how much they are in fact "losing" on average.
|
| I also wonder how much pressure it puts on MGM - who are no
| doubt very much aware of the loss (every major outage I've been
| on eventually comes down to how much did this cost us - whether
| it's money, customer attrition, customer trust etc) vs how much
| pressure it puts on executives following along to maybe pay
| attention to their IT and security teams. Pipe dream.
| RandallBrown wrote:
| You're getting a lot of comments to the contrary, but I agree
| with you.
|
| There is a difference between losing money (like someone is
| actually stealing the money) and not getting money you were
| hoping/expecting to get. In this context it can even be a
| little bit confusing since there are criminals involved that
| could actually be stealing money.
|
| Language has lots of ambiguities and despite this being a
| common way of describing this situation, I don't like it. Some
| people don't like the word "moist" either and that's just fine.
| It's an opinion.
| paulddraper wrote:
| > I never like it when writers use the word "lose" to describe
| money not earned.
|
| What the difference between not earning $8M and earning $8M and
| losing it?
|
| Bank account looks pretty similar.
| NegativeK wrote:
| There's an implied "losing $X [in comparison to expected
| revenue]" every time they say it.
|
| It's a reasonable perspective from accounting and, in my mind,
| a reasonable shorthand. For a more literal version of losing,
| people would be saying misplacing or stealing.
| SeanAnderson wrote:
| Huh? Google says MGM Resorts opex for 2022 11.6B or 31M/day,
| net income 1.4B or 3.8M/day.
|
| It doesn't seem unreasonable to say they are, in fact, losing
| 8.4M/day to opex.
| slashdev wrote:
| Money not earned is equivalent to money lost in this case. It
| will affect their quarterly results the same way.
| snickerbockers wrote:
| How is it even possible for all aspects of such a massive
| enterprise to all share a single point of failure like that? And
| why can't they just cut their losses on the past N days of
| business, restore all these servers from snapshots and get back
| to business?
| specialp wrote:
| There are multiple things that are done here. Suppose you had
| great, immutable backups. They still have many things that can
| ruin your business
|
| 1. Restoring networks, servers, third party services with
| knowledge that anything you restore could be compromised as
| well. Keys
|
| 2. The attackers will then threaten to dump all of your private
| information.
|
| It is more than just restoring data, it is restoring and
| resetting your entire infrastructure. And most places have
| backups, but they don't practice entire restores
| baby_souffle wrote:
| > And most places have backups, but they don't practice
| entire restores
|
| Or worse, they only practice part of it. Only once in my
| career have I seen a "restore.txt" that didn't start with
| something along the lines of "connect to $server".
|
| Ok, that assumes a LOT is already in place. Where is the
| "restore.txt" that goes over how to get $network up so that I
| can resolve the IP(s) for the server I need to restore?
|
| I can't prove it, but I suspect that most businesses know
| deep down that they _cant_ do a "black start" and they know
| that even a practice run is likely to find some pretty basic
| and embarrassing issues that will just be too costly to
| address.
| SteveNuts wrote:
| Often the attackers wait until the retention policy for backups
| has been hit before unleashing the payload of ransomware.
|
| This way, even if you have a snapshot from 7 days ago, it's
| also infected.
|
| Or even worse they have physical access to the backup
| server/storage and just delete backups infect them as well.
| jachee wrote:
| "The DR planning meeting has been once again postponed until
| next quarter..."
|
| Some middle-manager somewhere, probably.
| not_real_acct wrote:
| Maybe they shouldn't have their corporate login page on the
| Internet.
|
| https://mgmresorts.okta.com/app/mgmresortsprod_neocaseemploy...
| guestbest wrote:
| People are saving up to $8.4M a day due to cyberattack, and
| gambling addicts are being spared, analysts say
| SnorkelTan wrote:
| Yep. They definitely can't walk down the street to another
| casino to make poor decisions.
| mrguyorama wrote:
| Ah yes, a physical addiction is "Poor decisions", like being
| born poor is a poor decision
| ToDougie wrote:
| They can walk somewhere else. They don't have a disease.
| jiofj wrote:
| Imagine being one of the guys in charge of cybersecurity of MGM.
| I would dig a hole and hide.
| graton wrote:
| Or they have been telling management for years that security
| needs to be improved and more spending is needed to do that but
| management declined to provide funding.
| Freedom2 wrote:
| It's still on the onus of the employee to properly state
| their viewpoint and deliver a proper business document,
| outlining the risks and benefits. Too many times I've seen
| security been increased and upgraded, at the cost of the
| entire business shutting down, or even worse, layoffs.
| jszymborski wrote:
| The cybersecurity team will probably take the fall for it, but
| if I had to take a guess, their budget was probably no where
| near where it should be for a team that is responsible for
| protecting $8.4M of revenue a day.
| [deleted]
| fortran77 wrote:
| It took a while to find their CTO, he's also head of "Strategy"
| and "Innovation"
|
| https://investors.mgmresorts.com/investors/news-releases/pre...
| insanitybit wrote:
| If you're the CISO or whatever it's basically your job to get
| fired when this happens tbh
| not_real_acct wrote:
| This didn't age well:
|
| _" [Okta] is one of the things that I can put in my toolkit
| to say, 'Hey, we're gonna move faster because we have this
| identity component nailed._
|
| _Scott Howitt, CISO, MGM Resorts International "_
|
| That's a testimony from Okta's website.
| ComputerGuru wrote:
| I think those heads are on the chopping block no matter which
| hole they're hiding in.
| NegativeK wrote:
| I'd say that responsible organizations know that a hack is
| inevitable and you evaluate based on the response, but I've
| heard from people who've worked at MGM in the past that the
| place is disgustingly cutthroat.
| Sytten wrote:
| Bold of you to assume there was one (before the incident) /s
___________________________________________________________________
(page generated 2023-09-19 23:02 UTC)