[HN Gopher] MGM losing up to $8.4M a day due to cyberattack, ana...
       ___________________________________________________________________
        
       MGM losing up to $8.4M a day due to cyberattack, analyist says
        
       Author : gmays
       Score  : 111 points
       Date   : 2023-09-19 16:39 UTC (6 hours ago)
        
 (HTM) web link (www.reviewjournal.com)
 (TXT) w3m dump (www.reviewjournal.com)
        
       | justsomehnguy wrote:
       | > MGM is not earning up to $8.4M a day due not spending $333.3k a
       | day for a proper measures against cyberattack, analyist says
       | 
       | Fixed
        
       | zephyrus76 wrote:
       | This really feels like 1650's nautical piracy. Someone outside
       | the reach of the law of the targeted country's merchants, making
       | tons of money by theft and ransom. And like the pirates of old,
       | often supported by the host nation so long as their attacks
       | disrupt the activities of rivals nations' merchants.
        
         | willis936 wrote:
         | Merchants provide a value to society and pirates harm that. The
         | thieves are providing a value to society in this case by
         | damaging casinos, which provide no value to society and only
         | harm citizens.
        
           | dfxm12 wrote:
           | More than casinos are being damaged. There's also hotels,
           | restaurants, etc.
        
           | kube-system wrote:
           | Casinos provide leisure and entertainment. If what you're
           | actually trying to say is that they are overall a net harm,
           | then I'd point out that imperial mercantilism was also quite
           | harmful to many people. At least MGM hasn't overthrown any
           | countries.
        
             | mrguyorama wrote:
             | In exactly the same way a heroin dealer provides leisure
             | and entertainment. Selling access to an inherently
             | addictive substance should not be a for profit endeavor.
             | The incentives are inherently biased towards harming people
             | for profit.
        
               | kube-system wrote:
               | You say this as if "addictive" and "harmful" are boolean
               | concepts. These concepts have a wide spectrum in reality.
               | People die every day from addictions to all kinds of
               | socially acceptable products and services, whether it be
               | the dopamine rush from an unhealthy or dangerous
               | activity, a buzz from their favorite beverage, or the
               | sugar rush from an unhealthy snack.
        
               | willis936 wrote:
               | I encourage you to walk through some casinos and take
               | stock of what you see. The scales of enrichment and
               | addiction are nowhere near the balance of candy and soda.
        
           | paulddraper wrote:
           | Depends on what the merchant is selling, I reckon.
        
         | nosmokewhereiam wrote:
         | Cyber privateering was mentioned like 10-12 years ago. Someone
         | had a blog or similar referring to the 'Morgan doctrine'.
         | 
         | Edit: I found it. It looks more professionally edited and
         | lengthy than when I first came across it in 2010(!).
         | 
         | Link: https://www.themorgandoctrine.com/2010/11/draft-01-cyber-
         | pri...
         | 
         | The Cyber Privateer Code (draft 02--updated on 6/28/2013): -
         | Any unauthorized attempt to access your computer or phish your
         | data access privileges constitutes a crime punishable by the
         | looting of the attacker's assets by an authorized cyber
         | privateer. All assets. Within 6 months of the attack.
         | 
         | - If it is determined that the attacker is acting under
         | explicit instructions from a larger organization or government,
         | the assets of that organization or government are also forfeit
         | to the extent that an authorized cyber privateer may confiscate
         | them within a six month period of the original motivating
         | attack. All assets.
         | 
         | - The individual whose assets were seized by a cyber privateer
         | --or the publicly and legally designated spokesperson for the
         | organization or government whose assets were seized by the
         | cyber privateer--has the "right of parley" with the head of the
         | cyber privateering organization, such meeting to take place
         | online in a two-way video conference, such conference to be
         | publicly recorded by one or both parties and before the
         | disposition of the booty but no later than 10 days from the
         | confiscation.
         | 
         | - Innocent victims whose assets are directly and mistakenly
         | confiscated by cyber privateers (and whose funds are not
         | returned within 10-days after the parley) shall be compensated
         | in an amount equal to four times their loss, with interest
         | accruing on the restitution amount at the rate of twelve
         | percent per annum. This does not include victims of the cyber
         | criminals, since they were already victimized.
         | 
         | - Notifications and requests for parley must be unambiguously
         | left by the cyber privateer so as to allow the right of parley
         | to be exercised in a timely fashion.
         | 
         | *These rules would of course lead to the worlds end in any
         | significant conflict, imo. But it would certainly be fun for a
         | minute.
        
           | tpmx wrote:
           | Many of us foresaw this (and _much_ worse) when we first
           | heard about Bitcoin in 2009-2011. Yes, Bitcoin has its
           | anonymity issues, but cryptocurrencies in general is what
           | typically enables this kind of crime.
           | 
           | Example:
           | 
           | https://www.bloomberg.com/news/articles/2023-09-13/caesars-e.
           | ..
           | 
           | https://archive.ph/8BCDb
           | 
           |  _Caesars Entertainment Inc. paid tens of millions of dollars
           | to hackers who broke into the company's systems in recent
           | weeks and threatened to release the company's data, according
           | to two people familiar with the matter._
           | 
           |  _Hacking gangs typically ask to be paid in cryptocurrency if
           | they demand a ransom._
           | 
           | I don't want to live in a world with 100% anonymous and
           | untraceable payments.
        
             | distortionfield wrote:
             | > I don't want to live in a world with 100% anonymous and
             | untraceable payments.
             | 
             | Cash is equally as capable of this, though. The hackers in
             | this situation could demand cash and practically nothing
             | would change about the technical aspects of their attack.
        
               | tpmx wrote:
               | It's not.
               | 
               | They would have to travel from e.g. Russia to Las Vegas
               | to pick up the cash though. Or, I suppose, demand
               | delivery of cash to Russia, or some other place.
               | Whichever way, it's a lot easier for law enforcement.
               | Suddenly a particular country is responsible.
        
         | nico wrote:
         | It never stopped, and the US is one of the worst offenders
         | 
         | Check out War is a Racket, by US general Smedley Butler
         | 
         | Also the Snowden documents and the whole Asange/Wikileaks case
        
           | pphysch wrote:
           | The "World's Policeman" thesis really fell flat.
           | 
           | There is an urgent need to have effective international law-
           | enforcement and justice.
        
             | mcpackieh wrote:
             | > _There is an urgent need to have effective international
             | law-enforcement and justice._
             | 
             | What makes you think any other organization given such
             | privilege would do any better with it than the US? Even if
             | they started out with good intentions, that kind of power
             | will inevitably corrupt them.
             | 
             | Embrace multipolarity. Benevolent, wise and just
             | unipolarity will never happen.
        
             | infamouscow wrote:
             | Urgent to whom? We live in a multipolar world now.
             | 
             | Countries already use criminals as political tools to
             | advance their goals on the world stage. What makes you
             | think expanding these efforts will somehow change existing
             | geopolitical behavior?
             | 
             | All systems of law break down into the imposers, and the
             | imposed upon. You don't have to impose anything on the
             | voluntarily compliant, but what about those that refuse?
             | Are you going to invade or kill innocent people just
             | because a few leaders don't want to play by your rules?
             | 
             | Sanctions don't work for their intended political purpose.
             | The only reason politicians talk about them is because it
             | enables their corporate masters to swoop into markets and
             | make a lot of money. (And if you disagree, I ask you find a
             | study pointing to how sanctions were politically
             | successful.)
        
           | [deleted]
        
         | readyplayernull wrote:
         | Will we see machineguns and hacker hanging cages installed in
         | their buildings?
        
         | lainga wrote:
         | God damn them all, I was told / we'd abuse the C's for American
         | gold...
        
           | zephyrus76 wrote:
           | We'd file no bugs / thread no peers...
        
         | [deleted]
        
       | irtefa wrote:
       | I'm curious if MGM fully understood their cyber risks. Many
       | companies underestimate threats until something like this
       | happens. After seeing MGM, if other hotels beef up security too
       | (very likely), will overall costs for consumers go up?
        
         | commandlinefan wrote:
         | > underestimate threats until something like this happens
         | 
         | And then, when it does, they blame the people who were pointing
         | out the risks and suggesting solutions rather than the people
         | who were ignoring those people the whole time.
        
         | xfitm3 wrote:
         | Security is a SG&A line item, I am sure they are far more
         | fixated on physical security due to their business vertical and
         | had a gap. There will be many cyber companies chomping at the
         | bit to get a piece of the inevitable (I made this number up)
         | 100m MGM will spend on Cybersecurity over the next 5 years.
         | 
         | They won't make the same mistake twice and will build a
         | comprehensive cybersecurity program, and it will succeed. Up
         | until someone questions this cost and they forgot what they are
         | paying for because everything was so smooth and repeat the
         | cycle.
         | 
         | The objective of security is risk identification and
         | management, not creating an impervious barrier for potential
         | adversaries.
        
           | thefourthchime wrote:
           | " They won't make the same mistake twice and will build a
           | comprehensive cybersecurity program, and it will succeed. Up
           | until someone questions this cost and they forgot what they
           | are paying for because everything was so smooth and repeat
           | the cycle."
           | 
           | You couldn't have said it better.
        
         | jarym wrote:
         | > Many companies underestimate threats until something like
         | this happens
         | 
         | Speaking from my experience, many don't understand the threats
         | even after an incident. The reaction is often to add 'more
         | security' under any name. More restrictive policies, more
         | scanning, more layers of MFA - just blindly layering on things
         | because it's seen as 'more secure' without properly
         | understanding how it affects risk is an awful approach to
         | managing security.
        
           | justin_oaks wrote:
           | The goal is to make the boss feel more secure. And there are
           | plenty of snake oil salesmen willing to sell to that boss.
        
           | anotheruser13 wrote:
           | And I would say T-Mobile not only doesn't understand the
           | threats after their many data breaches, they have
           | continuously failed to improve Cybersecurity.
           | 
           | They have an incredibly crusty, buggy billing system written
           | in PowerBuilder, and I swear it's a holdover from the Voice
           | stream days
           | 
           | Disclaimer: Worked there in Tech Support.
        
       | raydiatian wrote:
       | analyist
        
       | bob1029 wrote:
       | This is a good example of the kind of case study I will point to
       | when someone starts to get cranky with my unyielding principle of
       | putting the _entire_ business inside a single SQL database.
       | 
       | When you have geo replicas and point-in-time restoration
       | capabilities which can synchronously bring 100% of the business
       | back from the dead in a matter of seconds/minutes...
       | 
       | How many $8.4m days before a complete rewrite of all systems
       | would be justified? If you are going to entertain a rewrite, why
       | not use one system to rule them all so you can audit one thing
       | and move on with life?
       | 
       | This industry does not seem like a good fit for non-traditional
       | technology stacks. I'd strongly consider putting my entire casino
       | on a mainframe if I could. Any vendor who indicates a lack of
       | willingness for integration with that tech stack would be
       | instantly disqualified from selection. I feel like this is a
       | really good technology bullshit filter for the kind of industry
       | MGM is operating in. If it's not good enough for Visa or Amex,
       | it's not good enough for a gambling operation.
        
         | sentimentscan wrote:
         | It seems like a bug/wrong infra, nothing that mainframe could
         | fix. >it's not good enough for Visa or Amex, it's not good
         | enough for a gambling operation. We have multicloud/kubernetes
        
         | paulddraper wrote:
         | What was their tech stack?
        
       | insanitybit wrote:
       | > Katz told investors in his Thursday and Sunday reports that
       | damages from the cyberattack at MGM would be claimed against
       | insurance, but it's unclear just how much would be covered.
       | 
       | I'm curious to see how this plays out. After all, if MGM is
       | audited and found to have been negligent, would insurance pay out
       | at all?
        
         | crazygringo wrote:
         | Presumably the insurance requires a security audit (yearly?) in
         | order to get in the first place?
         | 
         | As long as the auditors OK'd it then the insurance should pay
         | out. Unless they can show that MGM intentionally lied in the
         | information they gave the auditors -- which will surely now be
         | gone through with a fine-toothed comb.
         | 
         | (See that HN thread from a couple of days ago wondering if they
         | were personally liable for fraud for producing a document lying
         | about pentesting.)
        
           | insanitybit wrote:
           | The audits you get for something like SOC2 are quite weak,
           | I'm very curious to learn if the insurance team's audit is
           | more thorough (if they perform one).
        
       | Eji1700 wrote:
       | I suspect that's just an initial breakdown. They're estimating
       | 4.2 to 8.4 million a day out of the 42 million they normally
       | make, but that's just on the revenue side.
       | 
       | Equipment, man hours, botched projects, and lawsuits are going to
       | push that number waaay higher, and even then I feel like it's got
       | to be pretty low given the vast amount of money that passes
       | through every day. On a 15% hold 42 million would work out to 280
       | billion of flow through the slots max (and obviously that's
       | estimating high and assuming all revenue is from slots).
       | 
       | So 8 million a day is $53 billion in coin in that's not
       | occurring? Maybe that's correct.
       | 
       | Doing quick napkin math so pardon any errors.
        
       | kneel wrote:
       | MGM is smart for not paying.
       | 
       | You can't let the scammers dictate what a casino does, MGM is
       | already in the business of scamming people. They'll build their
       | whole system from the ground up and be incredibly resistant to
       | future attacks.
        
         | whycome wrote:
         | Gotta pay to play. What if the scammers told MGM they could
         | play a game of chance to get their money back?
        
       | anonymousiam wrote:
       | I never like it when writers use the word "lose" to describe
       | money not earned. Yeah, MGM is not earning as much as it could
       | because of this attack. They are under pressure to settle with
       | the attackers. Articles like this can increase that pressure. I'm
       | glad that they aren't settling, and I'm certain that they will
       | survive this attack.
        
         | rahimnathwani wrote:
         | If your employer gives you 2 weeks notice of employment
         | termination, did you lose your job?
         | 
         | After all, it only applies to future payroll periods.
        
           | eddieroger wrote:
           | Yes you lost your job, and will not receive money in the
           | future. Money from a job is in exchange for services rendered
           | to company. It's reasonable to say you can't lose something
           | you haven't yet received, but it is also normal to say
           | they're losing money given they had an incredibly high
           | likelihood of actually receiving it.
        
         | PopAlongKid wrote:
         | The revenue may be going down, but that doesn't mean they have
         | to operate at a loss (they could always cut their variable
         | expenses to match the cut in revenue). It would be more
         | accurate, but not as click-baity, to describe it as "MGM
         | getting up to $8.4M less revenue a day".
         | 
         | A slightly more misleading use of "losing money" is for example
         | when movie or music companies claim they are "losing" billions
         | of dollars to piracy, when there is no reason to believe that
         | every pirated copy would instead be purchased at full price, if
         | only piracy were eliminated.
        
         | SoftTalker wrote:
         | If your salary was cut 20% next year, would you think you were
         | not losing money because you had not yet earned it?
        
         | kube-system wrote:
         | It's a loss of income. This is a common use of the word.
        
           | bqmjjx0kac wrote:
           | Well, it's a loss of projected income, which in many ways is
           | not real.
        
             | CamelCaseName wrote:
             | It's not even that, it's revenue.
             | 
             | > MGM Resorts International could be losing between $4.2
             | million and $8.4 million in daily revenue
        
               | kube-system wrote:
               | Revenue _is_ a measure of income. Unless speaking about
               | specific types of revenue or specific types of income,
               | they are synonymous.
        
               | hollerith wrote:
               | Accounts don't think revenue and income are synomymous:
               | income is revenue minus expenses. Now if you were to say
               | that profit and income are synonymous, that I might be
               | okay with.
        
               | kube-system wrote:
               | Revenue minus expenses is " _net_ income ". "income" is
               | ambiguous.
        
               | [deleted]
        
             | kube-system wrote:
             | It is just plain normal language to refer to a loss as a
             | comparison against a current trajectory or current state.
             | It is reasonable to assume that the reader/listener knows
             | that the future cannot be predicted exactly, because this
             | is generally true. This is why it isn't said explicitly.
             | 
             | It would be silly to correct someone who said "I just
             | accepted a $120,000/yr job" with "you don't really know for
             | sure, you could get fired or die". The colloquial
             | presumption is that the rate of future income cited is
             | dependent on a steady trajectory without confounding
             | variables.
        
             | Groxx wrote:
             | It's real enough that companies regularly borrow against
             | it, which is about as real as anything is with money.
        
             | JumpCrisscross wrote:
             | > _it 's a loss of projected income, which in many ways is
             | not real_
             | 
             | About as real as money.
        
             | paulddraper wrote:
             | It's more real than not.
        
         | libraryatnight wrote:
         | There's lots of instances where I'd agree, but this one seems
         | like a tried and true business with years of revenue to gauge
         | how much they are in fact "losing" on average.
         | 
         | I also wonder how much pressure it puts on MGM - who are no
         | doubt very much aware of the loss (every major outage I've been
         | on eventually comes down to how much did this cost us - whether
         | it's money, customer attrition, customer trust etc) vs how much
         | pressure it puts on executives following along to maybe pay
         | attention to their IT and security teams. Pipe dream.
        
         | RandallBrown wrote:
         | You're getting a lot of comments to the contrary, but I agree
         | with you.
         | 
         | There is a difference between losing money (like someone is
         | actually stealing the money) and not getting money you were
         | hoping/expecting to get. In this context it can even be a
         | little bit confusing since there are criminals involved that
         | could actually be stealing money.
         | 
         | Language has lots of ambiguities and despite this being a
         | common way of describing this situation, I don't like it. Some
         | people don't like the word "moist" either and that's just fine.
         | It's an opinion.
        
         | paulddraper wrote:
         | > I never like it when writers use the word "lose" to describe
         | money not earned.
         | 
         | What the difference between not earning $8M and earning $8M and
         | losing it?
         | 
         | Bank account looks pretty similar.
        
         | NegativeK wrote:
         | There's an implied "losing $X [in comparison to expected
         | revenue]" every time they say it.
         | 
         | It's a reasonable perspective from accounting and, in my mind,
         | a reasonable shorthand. For a more literal version of losing,
         | people would be saying misplacing or stealing.
        
         | SeanAnderson wrote:
         | Huh? Google says MGM Resorts opex for 2022 11.6B or 31M/day,
         | net income 1.4B or 3.8M/day.
         | 
         | It doesn't seem unreasonable to say they are, in fact, losing
         | 8.4M/day to opex.
        
         | slashdev wrote:
         | Money not earned is equivalent to money lost in this case. It
         | will affect their quarterly results the same way.
        
       | snickerbockers wrote:
       | How is it even possible for all aspects of such a massive
       | enterprise to all share a single point of failure like that? And
       | why can't they just cut their losses on the past N days of
       | business, restore all these servers from snapshots and get back
       | to business?
        
         | specialp wrote:
         | There are multiple things that are done here. Suppose you had
         | great, immutable backups. They still have many things that can
         | ruin your business
         | 
         | 1. Restoring networks, servers, third party services with
         | knowledge that anything you restore could be compromised as
         | well. Keys
         | 
         | 2. The attackers will then threaten to dump all of your private
         | information.
         | 
         | It is more than just restoring data, it is restoring and
         | resetting your entire infrastructure. And most places have
         | backups, but they don't practice entire restores
        
           | baby_souffle wrote:
           | > And most places have backups, but they don't practice
           | entire restores
           | 
           | Or worse, they only practice part of it. Only once in my
           | career have I seen a "restore.txt" that didn't start with
           | something along the lines of "connect to $server".
           | 
           | Ok, that assumes a LOT is already in place. Where is the
           | "restore.txt" that goes over how to get $network up so that I
           | can resolve the IP(s) for the server I need to restore?
           | 
           | I can't prove it, but I suspect that most businesses know
           | deep down that they _cant_ do a "black start" and they know
           | that even a practice run is likely to find some pretty basic
           | and embarrassing issues that will just be too costly to
           | address.
        
         | SteveNuts wrote:
         | Often the attackers wait until the retention policy for backups
         | has been hit before unleashing the payload of ransomware.
         | 
         | This way, even if you have a snapshot from 7 days ago, it's
         | also infected.
         | 
         | Or even worse they have physical access to the backup
         | server/storage and just delete backups infect them as well.
        
         | jachee wrote:
         | "The DR planning meeting has been once again postponed until
         | next quarter..."
         | 
         | Some middle-manager somewhere, probably.
        
         | not_real_acct wrote:
         | Maybe they shouldn't have their corporate login page on the
         | Internet.
         | 
         | https://mgmresorts.okta.com/app/mgmresortsprod_neocaseemploy...
        
       | guestbest wrote:
       | People are saving up to $8.4M a day due to cyberattack, and
       | gambling addicts are being spared, analysts say
        
         | SnorkelTan wrote:
         | Yep. They definitely can't walk down the street to another
         | casino to make poor decisions.
        
           | mrguyorama wrote:
           | Ah yes, a physical addiction is "Poor decisions", like being
           | born poor is a poor decision
        
             | ToDougie wrote:
             | They can walk somewhere else. They don't have a disease.
        
       | jiofj wrote:
       | Imagine being one of the guys in charge of cybersecurity of MGM.
       | I would dig a hole and hide.
        
         | graton wrote:
         | Or they have been telling management for years that security
         | needs to be improved and more spending is needed to do that but
         | management declined to provide funding.
        
           | Freedom2 wrote:
           | It's still on the onus of the employee to properly state
           | their viewpoint and deliver a proper business document,
           | outlining the risks and benefits. Too many times I've seen
           | security been increased and upgraded, at the cost of the
           | entire business shutting down, or even worse, layoffs.
        
         | jszymborski wrote:
         | The cybersecurity team will probably take the fall for it, but
         | if I had to take a guess, their budget was probably no where
         | near where it should be for a team that is responsible for
         | protecting $8.4M of revenue a day.
        
           | [deleted]
        
         | fortran77 wrote:
         | It took a while to find their CTO, he's also head of "Strategy"
         | and "Innovation"
         | 
         | https://investors.mgmresorts.com/investors/news-releases/pre...
        
         | insanitybit wrote:
         | If you're the CISO or whatever it's basically your job to get
         | fired when this happens tbh
        
           | not_real_acct wrote:
           | This didn't age well:
           | 
           |  _" [Okta] is one of the things that I can put in my toolkit
           | to say, 'Hey, we're gonna move faster because we have this
           | identity component nailed._
           | 
           |  _Scott Howitt, CISO, MGM Resorts International "_
           | 
           | That's a testimony from Okta's website.
        
         | ComputerGuru wrote:
         | I think those heads are on the chopping block no matter which
         | hole they're hiding in.
        
           | NegativeK wrote:
           | I'd say that responsible organizations know that a hack is
           | inevitable and you evaluate based on the response, but I've
           | heard from people who've worked at MGM in the past that the
           | place is disgustingly cutthroat.
        
         | Sytten wrote:
         | Bold of you to assume there was one (before the incident) /s
        
       ___________________________________________________________________
       (page generated 2023-09-19 23:02 UTC)