{"id":23202,"date":"2023-10-30T08:37:51","date_gmt":"2023-10-30T16:37:51","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2023\/10\/30\/news-16932\/"},"modified":"2023-10-30T08:37:51","modified_gmt":"2023-10-30T16:37:51","slug":"news-16932","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2023\/10\/30\/news-16932\/","title":{"rendered":"MGM attack is too late a wake-up call for businesses, says James Fair: Lock and Code S04E22"},"content":{"rendered":"<p><em>This week on the Lock and Code podcast&#8230;<\/em><\/p>\n<p>In September, the Las Vegas casino and hotel operator MGM Resorts became a trending topic on social media&#8230; but for all the wrong reasons.&nbsp;A TikTok user posted a video taken from inside the casino floor of the MGM Grand&mdash;the company&#8217;s flagship hotel complex&nbsp;near the southern end of the Las Vegas strip&mdash;that didn&#8217;t&nbsp;involve the whirring of slot machines&nbsp;or the&nbsp;sirens and buzzers of sweepstake earnings, but, instead, row after row of&nbsp;digital gambling machines with blank, non-functional screens.&nbsp;That same TikTok user commented on their own post that it wasn&#8217;t just errored-out gambling machines that were causing problems&mdash;hotel guests&nbsp;were also having trouble getting into their own&nbsp;rooms.<\/p>\n<p>As the user said online about their own experience: &ldquo;Digital keys weren&rsquo;t working. Had to get physical keys printed. They doubled booked our room so we walked in on someone.&rdquo;<\/p>\n<p>The trouble didn&#8217;t stop there.<\/p>\n<p>A&nbsp;separate photo shared online allegedly showed what looked like a Walkie-Talkie affixed to an elevator&#8217;s handrail. Above the device was a piece of paper and a message written by hand:&nbsp;&ldquo;For any elevator issues, please use the radio for support.&rdquo;&nbsp;&nbsp;<\/p>\n<p>As the public would soon learn, MGM Resorts was the victim of a cyberattack, reportedly carried out by a group of&nbsp;criminals called Scattered Spider, which used the ALPHV ransomware.<\/p>\n<p>It was one of the most publicly-exposed cyberattacks in recent history. But just a few days before&nbsp;the public saw the end result, the same cybercriminal group received a reported $15 million ransom payment from a separate victim&nbsp;situated just one and a half miles away.<\/p>\n<p>On September 14, Caesar&rsquo;s Entertainment reported in a filing with the US Securities and Exchange Commission that it, too, had suffered a cyber breach, and according to reporting from CNBC, it received a $30 million ransom demand, which it then negotiated down by about 50 percent.<\/p>\n<p>The social media flurry, the TikTok videos, the comments and confusion from customers, the ghost-town casino floors captured in photographs&mdash;it all added up to something strange and new: Vegas&nbsp;was breached.&nbsp;<\/p>\n<p>But how?&nbsp;<\/p>\n<p>Though <a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2023-10-03\/mgm-cyberattack-shows-how-hackers-deploy-social-engineering\" target=\"_blank\" rel=\"nofollow\">follow-on reporting suggests a particularly effective social engineering scam<\/a>, the attacks themselves revealed a more troubling, potential vulnerability for businesses everywhere, which is that a company&#8217;s budget&mdash;and its relative ability to devote resources to cybersecurity&mdash;doesn&#8217;t necessarily insulate it from attacks.&nbsp;<\/p>\n<p>Today on the Lock and Code podcast with host David Ruiz, we speak with James Fair, senior vice president&nbsp;of IT Services at the managed IT services company Executech, about whether businesses are taking cybersecurity seriously enough, which industries&nbsp;he&#8217;s seen pushback&nbsp;from for initial cybersecurity recommendations (and why), and the frustration of seeing some companies only take cybersecurity seriously after a major attack.&nbsp;<\/p>\n<blockquote>\n<p>&#8220;How many do we have to see? MGM got hit, you guys. Some of the biggest targets out there&mdash;people who have more cybersecurity budget than people can imagine&mdash;got hit. So, what are you waiting for?&#8221;<\/p>\n<\/blockquote>\n<p>Tune in today&nbsp;to listen to the full conversation.<\/p>\n<p><iframe style=\"\" src=\"https:\/\/open.spotify.com\/embed\/episode\/2OhXW2GKcOujpEkXg3sxEw?utm_source=generator\" width=\"100%\" height=\"420\" frameborder=\"0\" allowfullscreen=\"\" allow=\"autoplay; clipboard-write; encrypted-media; fullscreen; picture-in-picture\" loading=\"lazy\"><\/iframe><\/p>\n<p>You can also find us on&nbsp;<a href=\"https:\/\/podcasts.apple.com\/us\/podcast\/lock-and-code\/id1500049667\" target=\"_blank\" rel=\"noreferrer noopener\">Apple Podcasts<\/a>,&nbsp;<a href=\"https:\/\/open.spotify.com\/show\/3VB1MCXNk76TSddNNZcDuo?si=b454MPzCTYWvvS5bOPdxcA\" target=\"_blank\" rel=\"noreferrer noopener\">Spotify<\/a>, and&nbsp;<a href=\"https:\/\/podcasts.google.com\/feed\/aHR0cHM6Ly9mZWVkLnBvZGJlYW4uY29tL2xvY2thbmRjb2RlL2ZlZWQueG1s\" target=\"_blank\" rel=\"noreferrer noopener\">Google Podcasts<\/a>, plus whatever preferred podcast platform you use.<\/p>\n<p><em>Show notes and credits:<\/em><\/p>\n<p>Intro Music: &ldquo;Spellbound&rdquo; by Kevin MacLeod (<a href=\"http:\/\/incompetech.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">incompetech.com<\/a>)<br \/>Licensed under Creative Commons: By Attribution 4.0 License<br \/><a href=\"http:\/\/creativecommons.org\/licenses\/by\/4.0\/\" target=\"_blank\" rel=\"noreferrer noopener\">http:\/\/creativecommons.org\/licenses\/by\/4.0\/<\/a><br \/>Outro Music: &ldquo;Good God&rdquo; by Wowa (unminus.com)<\/p>\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/podcast\/2023\/10\/mgm-attack-is-too-late-a-wakeup-call-lock-and-code-s04e22\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<table cellpadding=\"10\">\n<tr>\n<td valign=\"top\" align=\"left\">\n<p>Categories: <a href=\"https:\/\/www.malwarebytes.com\/blog\/category\/podcast\" rel=\"category tag\">Podcast<\/a><\/p>\n<p>This week on the Lock and Code podcast, we speak with James Fair about the reluctance of some businesses to take cybersecurity seriously, even in the face of major attacks. <\/p>\n<table width=\"100%\">\n<tr>\n<td align=\"right\">\n<p><b>(<a href=\"https:\/\/www.malwarebytes.com\/blog\/podcast\/2023\/10\/mgm-attack-is-too-late-a-wakeup-call-lock-and-code-s04e22\" title=\"MGM attack is too late a wake-up call for businesses, says James Fair: Lock and Code S04E22\">Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/www.malwarebytes.com\/blog\/podcast\/2023\/10\/mgm-attack-is-too-late-a-wakeup-call-lock-and-code-s04e22\">MGM attack is too late a wake-up call for businesses, says James Fair: Lock and Code S04E22<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/www.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[5820],"class_list":["post-23202","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-podcast"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/23202","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=23202"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/23202\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=23202"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=23202"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=23202"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}