top of page

CYBER & INFOSEC

"blogger, InfoSec specialist, super hero ... and all round good guy" 

DISCUSSIONS, CONCEPTS & TECHNOLOGIES FOR THE WORLD OF

JOIN THE DISCUSSION

Scattered Spider Members Indicted: Five Hackers Charged for MGM and Caesars Ransomware Attacks

  • May 19
  • 2 min read

Federal prosecutors have unsealed indictments against five alleged members of Scattered Spider, the cybercriminal group responsible for devastating ransomware attacks against MGM Resorts International and Caesars Entertainment in 2023. The charges include conspiracy, wire fraud, and identity theft. This marks one of the most significant cybercrime prosecutions in recent years targeting a Western-based, English-speaking threat group.

Scattered Spider, also tracked as UNC3944 and Octo Tempest, rose to infamy through a series of high-profile attacks using social engineering rather than technical exploits. The group specializes in calling corporate IT help desks, impersonating employees using personal data sourced from LinkedIn and data broker sites, and convincing help desk staff to reset multi-factor authentication. Once inside, they move laterally through hybrid Active Directory and Azure environments to deploy ransomware or exfiltrate data for extortion.

The MGM Resorts breach alone caused over $100 million in direct losses, disrupted hotel operations across Las Vegas for weeks, and exposed data on millions of guests. Caesars Entertainment quietly paid an estimated $15 million ransom. The group also targeted dozens of other organizations across retail, hospitality, and technology sectors in the US and UK. UK retailer Marks and Spencer and Co-op are among the most recent victims, having suffered attacks attributed to DragonForce affiliates using the Scattered Spider playbook.

Organizations most at risk are those with large hybrid workforces, outsourced IT help desks, and Entra ID or Okta-based identity platforms. Any company where a help desk agent can reset MFA over a phone call without strong out-of-band verification is vulnerable to the exact technique that enabled these attacks.

The indictments should not create a false sense that the threat has passed. CrowdStrike and others have documented that Scattered Spider's methodology has been absorbed by other RaaS affiliates who continue operating independently. Immediate defensive actions: remove help desk ability to reset MFA without video verification, enforce hardware token requirements for MFA resets, and audit all Entra ID Conditional Access policies for gaps that allow on-premises credential reuse in cloud environments.

These prosecutions represent the most direct accountability for a major ransomware operation in years, but the playbook these attackers pioneered has already spread far beyond any individual group.

Source: https://www.bleepingcomputer.com/news/security/scattered-spider-hackers-indicted-for-mgm-caesars-attacks/

6 Comments


BILL STEPHNIE
BILL STEPHNIE
11 hours ago

The Scattered Spider indictments show social engineering remains the weakest link. Great breakdown of the MGM and Caesars cases — I've been following the identity theft charges closely and it's eye-opening. https://3daimaker.com

Like

todahywu
May 21

This comparison between fog computing and edge computing was very well explained. Complex technological distinctions hydrostatic pressure test can be confusing, but your examples made everything accessible and easy to understand. appreciates educational tech content that empowers readers to stay informed about emerging innovations.

Like

todahywu
May 21

Congratulations to Ryan on this amazing cosmetic dentistry oakville achievement. Hard work and persistence truly pay off, and this celebration is well deserved. loves seeing milestones recognized and wishes continued success in all future endeavors.

Like

todahywu
May 21

Fantastic comparison between fog and edge computing. The distinctions were clearly explained, making this line of credit for nonprofit technical subject approachable for readers at all levels. appreciates educational posts like this that make emerging technologies easier to understand and apply.

Like

todahywu
May 21

Excellent comparison of fog and https://pettransportpro.com/ edge computing concepts. The distinctions are explained clearly and professionally. appreciates technical content that educates readers while simplifying complex innovations shaping the future.

Like

doctorchaos.com and drchaos.com is a blog dedicated to Cyber Counter Intelligence and Cybersecurity technologies. The posts will be a discussion of concepts and technologies that make up emerging threats and techniques related to Cyber Defense. Sometimes we get a little off-topic. Articles are gathered or written by cyber security professionals, leading OEMs, and enthusiasts from all over the world to bring an in-depth, real-world, look at Cyber Security. About this blog doctorchaos.com and drchaos.com and any affiliate website does not represent or endorse the accuracy or reliability of any information’s, content or advertisements contained on, distributed through, or linked, downloaded or accessed from any of the services contained on this website, nor the quality of any products, information’s or any other material displayed, purchased, or obtained by you as a result of an advertisement or any other information’s or offer in or in connection with the services herein. Everything on this blog is based on personal opinion and should be interoperated as such. Contact Info If you would like to contact this blog, you may do so by emailing ALAKHANI(AT)YMAIL(DOT)COM  

SOCIALS 

SUBSCRIBE 

Keeping you informed | Latest News

© 2018 Dr. Chaos 

bottom of page