I bet that right now there are at least 3 teams trying to understand this. One working for MGM's current IT vendor, one working for their cybersecurity insurance company, and another one hired by MGM's board independently to try to sort out exactly what the heck and make sure they aren't behind any info the insurance company finds out.

Unless they don't have cyber insurance