Site navigation

How Much did MGM Lose from its Recent Breach?

Michael Edgar

,

MGM ransomware
MGM Resorts reveals that a recent ransomware attack cost the company nearly $110 million (£89.6m).

MGM Resorts International, a major player in the global hospitality industry was the victim of a ransomware attack last month. The company is now saying the repercussions from the attack have resulted in roughly $110 million (£89.6m) in costs according to a recent 8-K filing with the Securities and Exchange Commission (SEC).

The company cited operational disruptions, as the primary driver behind this significant financial toll. MGM said the attack necessitated a rapid response, which involved taking critical systems offline to contain the threat to prevent threat actors from gaining access to sensitive customer bank account numbers or payment card information. The company believes that this swift reaction was essential in averting a potentially more catastrophic breach.

The company reports it lost about $100m (£81.5) from the breach, while $10m (£8.1m) came from one-time consulting and cleanup fees. While this might seem like a large price tag at first glance, the company drew in nearly $4 billion (£3.2bn) in revenue from the second quarter of last year alone. According to MGM, these losses will only slightly impact the Q3 financials. 

This comes on the backdrop of ransomware rates dropping, but it should be noted that the trend seems to suggest that threat actors are increasingly targeting high-earning companies for the biggest payoff. According to Sophos, the highest earning organisations are most likely to pay out to threat actors, with the average payout by companies with revenues over $5bn (£4bn) was about $2.5m (£2m). 


Recommended reading


Interestingly, MGM chose not to pay the ransom, based on the assumption that paying ransom to cyber-criminals does not guarantee a full return of systems and data, and could only further contribute to the development of the ransomware ecosystem. 

MGM confirmed that personal information of specific customers who had transacted with the company before March 2019 – such as names, contact details, gender, date of birth, and driver’s license numbers – had been accessed by the threat actors. Some Social Security and passport numbers were also obtained, however customer passwords, bank account numbers, and payment card information are believed to be safe from the breach.

The company’s cybersecurity insurance is expected to cover the financial losses and future expenses associated with the ransomware attack, but the full extent of the costs and related impacts is still under investigation.

Michael Edgar

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data