MGM Resorts International, a major player in the global hospitality industry was the victim of a ransomware attack last month. The company is now saying the repercussions from the attack have resulted in roughly $110 million (£89.6m) in costs according to a recent 8-K filing with the Securities and Exchange Commission (SEC).
The company cited operational disruptions, as the primary driver behind this significant financial toll. MGM said the attack necessitated a rapid response, which involved taking critical systems offline to contain the threat to prevent threat actors from gaining access to sensitive customer bank account numbers or payment card information. The company believes that this swift reaction was essential in averting a potentially more catastrophic breach.
The company reports it lost about $100m (£81.5) from the breach, while $10m (£8.1m) came from one-time consulting and cleanup fees. While this might seem like a large price tag at first glance, the company drew in nearly $4 billion (£3.2bn) in revenue from the second quarter of last year alone. According to MGM, these losses will only slightly impact the Q3 financials.
This comes on the backdrop of ransomware rates dropping, but it should be noted that the trend seems to suggest that threat actors are increasingly targeting high-earning companies for the biggest payoff. According to Sophos, the highest earning organisations are most likely to pay out to threat actors, with the average payout by companies with revenues over $5bn (£4bn) was about $2.5m (£2m).
Recommended reading
- Cyber Attack Exposes Data of 10.6 Million Guests at MGM Resorts
- Get What You Pay For: AI’s Hefty Price Tag Can’t be Lowered
- LinkedIn Hacking Campaign Illustrates Rise in Zero-Day Exploits
Interestingly, MGM chose not to pay the ransom, based on the assumption that paying ransom to cyber-criminals does not guarantee a full return of systems and data, and could only further contribute to the development of the ransomware ecosystem.
MGM confirmed that personal information of specific customers who had transacted with the company before March 2019 – such as names, contact details, gender, date of birth, and driver’s license numbers – had been accessed by the threat actors. Some Social Security and passport numbers were also obtained, however customer passwords, bank account numbers, and payment card information are believed to be safe from the breach.
The company’s cybersecurity insurance is expected to cover the financial losses and future expenses associated with the ransomware attack, but the full extent of the costs and related impacts is still under investigation.





