Just two weeks after the new Securities and Exchange Commission (SEC) cybersecurity disclosure rules went into effect, two major casino and hotel operators, Caesars Entertainment and MGM Resorts International, have filed Form 8-K reports with the agency, disclosing cyberattacks against their businesses.
The cybersecurity disclosure rules, effective since September 5, require enterprises to disclose “material” incidents within four business days.
In MGM’s report filed on September 13, 2023, the company briefly stated “On September 12, 2023, MGM Resorts International issued a press release regarding a cybersecurity issue involving the Company.”
In the press release it issued, MGM acknowledged the cyberattack. “MGM Resorts recently identified a cybersecurity issue affecting certain of the company's systems. Promptly after detecting the issue, we began an investigation with assistance from leading external cybersecurity experts. We also notified law enforcement and are taking steps to protect our systems and data, including shutting down certain systems,” the company wrote.
In the filing yesterday, Caesars reported the company “recently identified suspicious activity in its information technology network resulting from a social engineering attack on an outsourced IT support vendor.”
However, its customer-facing operations, including its physical properties, online and mobile gaming applications, have not been impacted by this cyber incident, according to the report.
MGM computer systems shut down by hackersThe cyberattack reportedly caused an outage to certain MGM's systems, taking offline the company's computer systems, slot machines and digital room keys at its Las Vegas properties.
The nature of the attack remains unknown and MGM has not yet confirmed if any customer data was stolen by the attackers. “Our investigation is ongoing, and we are working diligently to resolve the matter. The company will continue to implement measures to secure its business operations and take additional steps as appropriate,” the company said in the press release.
This event marks MGM's second significant cyber incident since 2019. The company suffered a data breach in which more than 10 million customer records including personally identifiable information were stolen by the hackers and later shared on a hacker forum.
Caesars takes action to remediate the attackAccording to Caesars’ Form 8-K, the company found an unauthorized actor acquired a copy of its loyalty program database among other data on September 7, 2023.
This database included sensitive information like driver's license numbers and Social Security numbers for a significant number of members.
After detecting this suspicious activity, Caesars launched an investigation, engaged leading cybersecurity firms for assistance, and notified law enforcement and state gaming regulators.
Although the company is still assessing the full extent of the breach, Caesars reports no evidence indicating the compromise of member passwords, bank account details or payment card information. It also does not expect the cyberattack will “have a material effect” on the company’s financial condition and results of operations.
“We have taken steps to ensure that the stolen data is deleted by the unauthorized actor, although we cannot guarantee this result. We are monitoring the web and have not seen any evidence that the data has been further shared, published or otherwise misused,” the company wrote in the SEC filing.
“The full scope of the costs and related impacts of this incident, including the extent to which these costs will be offset by our cybersecurity insurance or potential indemnification claims against third parties, has not been determined,” it added.
A wake-up call for the casino industryEven though the full scope of costs and related impacts of the MGM and Caesars incidents remain uncertain, these attacks are likely to serve as a wake-up call for the casino industry and others.
“It's important to note that social engineering, if it is indeed the root of this incident, can happen to any organization, no matter how sophisticated,” Arctic Wolf VP of Strategy Ian McShane said in a statement. “I’m almost certain that MGM isn’t underfunded or underinvested in cyber. I suspect this is just more proof that technology is not the silver bullet — people and process need to be continuously monitored and modified as the threat landscape changes. ”
McShane also predicts casino industry authorities might consider mandating specific cybersecurity requirements as part of the gambling license.
“Long term, given the precedence set in other industries, the recent disclosure rules added by the SEC, and the highly regulated nature of casinos in general, I wouldn’t be surprised if gaming/casino authorities take a look at mandating specific requirements relating to cybersecurity that are part of the gambling license,” he said.
Comments