Live data from Hacker News

MGM losing up to $8.4M a day due to cyberattack, analyist says

reviewjournal.com

61–70 of 111 posts

Re: MGM losing up to $8.4M a day due to cyberattack, analyist says

#61
post #3

Imagine being one of the guys in charge of cybersecurity of MGM. I would dig a hole and hide.

If you're the CISO or whatever it's basically your job to get fired when this happens tbh

This didn't age well:

"[Okta] is one of the things that I can put in my toolkit to say, ‘Hey, we're gonna move faster because we have this identity component nailed.

Scott Howitt, CISO, MGM Resorts International"

That's a testimony from Okta's website.

Re: MGM losing up to $8.4M a day due to cyberattack, analyist says

#62
post #44

MGM is smart for not paying. You can't let the scammers dictate what a casino does, MGM is already in the business of scamming people. They'll build their whole system from the ground up and be incredibly resistant to future attacks.

Gotta pay to play. What if the scammers told MGM they could play a game of chance to get their money back?

Re: MGM losing up to $8.4M a day due to cyberattack, analyist says

#63
This is a good example of the kind of case study I will point to when someone starts to get cranky with my unyielding principle of putting the entire business inside a single SQL database.

When you have geo replicas and point-in-time restoration capabilities which can synchronously bring 100% of the business back from the dead in a matter of seconds/minutes...

How many $8.4m days before a complete rewrite of all systems would be justified? If you are going to entertain a rewrite, why not use one system to rule them all so you can audit one thing and move on with life?

This industry does not seem like a good fit for non-traditional technology stacks. I'd strongly consider putting my entire casino on a mainframe if I could. Any vendor who indicates a lack of willingness for integration with that tech stack would be instantly disqualified from selection. I feel like this is a really good technology bullshit filter for the kind of industry MGM is operating in. If it's not good enough for Visa or Amex, it's not good enough for a gambling operation.

Re: MGM losing up to $8.4M a day due to cyberattack, analyist says

#64
post #11

I'm curious if MGM fully understood their cyber risks. Many companies underestimate threats until something like this happens. After seeing MGM, if other hotels beef up security too (very likely), will overall costs for consumers go up?

> underestimate threats until something like this happens

And then, when it does, they blame the people who were pointing out the risks and suggesting solutions rather than the people who were ignoring those people the whole time.

Re: MGM losing up to $8.4M a day due to cyberattack, analyist says

#65
post #43
post #38

Earlier quoted context omitted.

It never stopped, and the US is one of the worst offenders Check out War is a Racket, by US general Smedley Butler Also the Snowden documents and the whole Asange/Wikileaks case

The "World's Policeman" thesis really fell flat. There is an urgent need to have effective international law-enforcement and justice.

> There is an urgent need to have effective international law-enforcement and justice.

What makes you think any other organization given such privilege would do any better with it than the US? Even if they started out with good intentions, that kind of power will inevitably corrupt them.

Embrace multipolarity. Benevolent, wise and just unipolarity will never happen.

Re: MGM losing up to $8.4M a day due to cyberattack, analyist says

#66

How is it even possible for all aspects of such a massive enterprise to all share a single point of failure like that? And why can't they just cut their losses on the past N days of business, restore all these servers from snapshots and get back to business?

There are multiple things that are done here. Suppose you had great, immutable backups. They still have many things that can ruin your business 1. Restoring networks, servers, third party services with knowledge that anything you restore could be compromised as well. Keys 2. The attackers will then threaten to dump all of your private information. It is more than just restoring data, it is restoring and resetting you…

> And most places have backups, but they don't practice entire restores

Or worse, they only practice part of it. Only once in my career have I seen a "restore.txt" that didn't start with something along the lines of "connect to $server".

Ok, that assumes a LOT is already in place. Where is the "restore.txt" that goes over how to get $network up so that I can resolve the IP(s) for the server I need to restore?

I can't prove it, but I suspect that most businesses know deep down that they _cant_ do a "black start" and they know that even a practice run is likely to find some pretty basic and embarrassing issues that will just be too costly to address.

Re: MGM losing up to $8.4M a day due to cyberattack, analyist says

#67
post #3

Imagine being one of the guys in charge of cybersecurity of MGM. I would dig a hole and hide.

The cybersecurity team will probably take the fall for it, but if I had to take a guess, their budget was probably no where near where it should be for a team that is responsible for protecting $8.4M of revenue a day.

[deleted]

Re: MGM losing up to $8.4M a day due to cyberattack, analyist says

#68

This really feels like 1650's nautical piracy. Someone outside the reach of the law of the targeted country's merchants, making tons of money by theft and ransom. And like the pirates of old, often supported by the host nation so long as their attacks disrupt the activities of rivals nations' merchants.

Cyber privateering was mentioned like 10-12 years ago. Someone had a blog or similar referring to the 'Morgan doctrine'. Edit: I found it. It looks more professionally edited and lengthy than when I first came across it in 2010(!). Link: https://www.themorgandoctrine.com/2010/11/draft-01-cyber-pri... The Cyber Privateer Code (draft 02—updated on 6/28/2013): - Any unauthorized attempt to access your computer or phish…

Many of us foresaw this (and much worse) when we first heard about Bitcoin in 2009-2011. Yes, Bitcoin has its anonymity issues, but cryptocurrencies in general is what typically enables this kind of crime.

Example:

https://www.bloomberg.com/news/articles/2023-09-13/caesars-e...

https://archive.ph/8BCDb

Caesars Entertainment Inc. paid tens of millions of dollars to hackers who broke into the company’s systems in recent weeks and threatened to release the company’s data, according to two people familiar with the matter.

Hacking gangs typically ask to be paid in cryptocurrency if they demand a ransom.

I don't want to live in a world with 100% anonymous and untraceable payments.

Re: MGM losing up to $8.4M a day due to cyberattack, analyist says

#69
post #3

Imagine being one of the guys in charge of cybersecurity of MGM. I would dig a hole and hide.

It took a while to find their CTO, he's also head of "Strategy" and "Innovation"

https://investors.mgmresorts.com/investors/news-releases/pre...

Post reply on HN