MGM Resorts hacked and all systems down

Discussion in 'The Mainboard' started by GoodForAnother, Sep 11, 2023.

  1. GoodForAnother

    GoodForAnother the revolution will not be brought to you by Xerox
    Staff Donor TMB OG
    Kansas State WildcatsKansas City RoyalsKansas City ChiefsSporting Kansas CityTottenham HotspurBig 8 ConferenceBig 12 ConferenceCoors LightFormula 1

  2. $P1

    $P1 Ball State #1
    Staff Donor TMB OG
    Michigan WolverinesChicago CubsLos Angeles LakersChicago BearsChicago BlackhawksWest Ham UnitedBall State Cardinals

    Holy shit
     
    Artoo likes this.
  3. BayouMafia

    BayouMafia Thought Leader in Posting
    Staff Donor
    LSU TigersTexas RangersNew Orleans SaintsFulhamWrexham AFCDulwich Hamlet

  4. ned's head

    ned's head Well-Known Member
    Donor

    Imagine all of the furious seniors on the slots right now. Can't fathom the level of cruelty and hate they must be spewing
     
    Biship, Doc Louis, DUCKMOUTH and 24 others like this.
  5. joey jo-jo jr shabadoo

    joey jo-jo jr shabadoo you know for me, the action is the juice

  6. dblplay1212

    dblplay1212 Well-Known Member
    Donor TMB OG
    Alabama Crimson TideNew York YankeesJacksonville Jaguars2pacSneakersFormula 1

    How does one going about requesting a ransom from a company of that size? Email the CEO? Blast email the board? "Hey we got your whole shit, send Bitcoin to here."
     
  7. NCHusker

    NCHusker We named our yam Pam. It rhymed.
    Donor TMB OG
    Nebraska CornhuskersChicago CubsDenver NuggetsKansas City ChiefsAvengersUnited States Men's National Soccer TeamUSA BasketballBig 8 ConferenceBig Ten ConferenceNebraska Cornhuskers alt

    Communicating with leadership seems like one of the less challenging parts of this scheme to me
     
  8. nexus

    nexus TMB’s TSO
    Donor TMB OG
    Indiana HoosiersNotre Dame Fighting IrishChicago CubsIndianapolis ColtsPittsburgh PenguinsReal MadridTool

    Andy Garcia finds you
     
  9. Eric The Viking

    Eric The Viking Nitro, the All Knowing
    Donor TMB OG

    Sending a singing telegram to deliver the message, would be hilarious.
     
  10. dblplay1212

    dblplay1212 Well-Known Member
    Donor TMB OG
    Alabama Crimson TideNew York YankeesJacksonville Jaguars2pacSneakersFormula 1

    That's fair. idk what made that part pop in my head, just curious. Maybe a text tot he CEO or head of IT? I need details on how it plays out.
     
    NCHusker likes this.
  11. Handcuffed

    Handcuffed TMB OG
    Staff Donor
    Seattle MarinersOregon DucksPortland TimbersPortland Trail Blazers

    have they tried just unplugging the machines and plugging them back in?
     
  12. Prospector

    Prospector I am not a new member
    Donor
    Utah UtesArkansas Razorbacks

    They found the email in their spam folder next to the one from the Nigerian Prince.
     
  13. Taques

    Taques sometimes maybe good sometimes maybe shit
    Staff Donor TMB OG
    The Real Movement

    vegas right fellas?
     
    Fuzzy Zoeller and BudKilmer like this.
  14. $P1

    $P1 Ball State #1
    Staff Donor TMB OG
    Michigan WolverinesChicago CubsLos Angeles LakersChicago BearsChicago BlackhawksWest Ham UnitedBall State Cardinals

    In a lot of cases, the ransomware itself leaves details on who/what to contact.
     
  15. Name P. Redacted

    Name P. Redacted I have no money and I'm also gay
    Donor
    Kansas State WildcatsSeattle Kraken

    This is what they get for their sports betting lobbying
     
  16. dblplay1212

    dblplay1212 Well-Known Member
    Donor TMB OG
    Alabama Crimson TideNew York YankeesJacksonville Jaguars2pacSneakersFormula 1

    In the code? Or it pops up on the screen? We have to have a cyber security guy on here.
     
  17. Name P. Redacted

    Name P. Redacted I have no money and I'm also gay
    Donor
    Kansas State WildcatsSeattle Kraken

    You could look this up yourself for real
     
  18. nexus

    nexus TMB’s TSO
    Donor TMB OG
    Indiana HoosiersNotre Dame Fighting IrishChicago CubsIndianapolis ColtsPittsburgh PenguinsReal MadridTool

    the plot of season 2 of Mr. Robot details it all
     
    fattus, Lip, chasenwilliam and 9 others like this.
  19. AptosDuck

    AptosDuck Pedantic Hausfrau
    Donor
    California Golden Bears

    [​IMG]
     
  20. dblplay1212

    dblplay1212 Well-Known Member
    Donor TMB OG
    Alabama Crimson TideNew York YankeesJacksonville Jaguars2pacSneakersFormula 1

    That's what TMB is for
     
    40wwttamgib likes this.
  21. $P1

    $P1 Ball State #1
    Staff Donor TMB OG
    Michigan WolverinesChicago CubsLos Angeles LakersChicago BearsChicago BlackhawksWest Ham UnitedBall State Cardinals

    In our case, the file contained detailed instructions on how to make payment, no contact requested.

    We didn't pay because it was some simple shit, apparently.

    We did have an IT guy fired for it. Bad file he downloaded
     
  22. kennypowers

    kennypowers Big shit like a dinosaur did it
    Donor TMB OG
    UCF KnightsAtlanta BravesJacksonville Jaguars

  23. Tarpon Nole

    Tarpon Nole Well-Known Member
    Donor
    Florida State SeminolesTampa Bay RaysTampa Bay BuccaneersTampa Bay Lightning

    may company was part of the notpetnya attacks in 2017. The computers had this contact note on them, but they ended up realizing it wasn’t a ransomware attack

    was one of the wildest mornings of my life walking in and seeing that on all the computers and then going upstairs to IT and it just being a war zone “unplug that? No don’t unplug anything!” While on with the server people who were on with the FBI
     
  24. GoodForAnother

    GoodForAnother the revolution will not be brought to you by Xerox
    Staff Donor TMB OG
    Kansas State WildcatsKansas City RoyalsKansas City ChiefsSporting Kansas CityTottenham HotspurBig 8 ConferenceBig 12 ConferenceCoors LightFormula 1

    usually by Bitcoin and yes there is insurance for it to answer your next question dbl
     
  25. $P1

    $P1 Ball State #1
    Staff Donor TMB OG
    Michigan WolverinesChicago CubsLos Angeles LakersChicago BearsChicago BlackhawksWest Ham UnitedBall State Cardinals

    Yeah in my company, I'm sure there's been other attacks. The only reason I know the details of this exact case is because I was the one that stumbled onto it. I start work around 6am most days, even rolling into the office pre-COVID at that time. Our old phone system stored .wavs for our IVR in a network drive and I went to update one and it was locked. Then I noticed the entire folder was locked. Then I noticed every file in every folder in that network drive was locked. Then I noticed every file's last change was from the same user. Then I found a .txt file. Then I called our CIO.
     
  26. Tarpon Nole

    Tarpon Nole Well-Known Member
    Donor
    Florida State SeminolesTampa Bay RaysTampa Bay BuccaneersTampa Bay Lightning

    I think they said they traces ours back to someone over in Germany or something who fell for a phishing attack. We were legitimately shit down for 2 weeks. Windows, the fbi, and some people from overseas all came in to try and fix. They had to rebuild essentially everything

    they’ve sent those really obvious test emails like 1-2 times a month since then. The first one after the attack, the IT group had like a a 1-3 fail rate and the CIO lost his shit
     
  27. Handcuffed

    Handcuffed TMB OG
    Staff Donor
    Seattle MarinersOregon DucksPortland TimbersPortland Trail Blazers

    not the screen, at least in this case

    the slot machines and hotel screens are all just showing the same image right now:

    [​IMG]
     
  28. devine

    devine hi, i am user devine
    Donor
    West Virginia MountaineersMilwaukee BucksPhoenix SunsPittsburgh PenguinsSan Diego PadresBarAndGrillCoors Light

    I feel bad for whatever poor mgm employee clicked the phishing email
     
  29. Tarpon Nole

    Tarpon Nole Well-Known Member
    Donor
    Florida State SeminolesTampa Bay RaysTampa Bay BuccaneersTampa Bay Lightning

    Imagine walking into work at like 7:30 and seeing this everywhere
    upload_2023-9-11_18-11-52.png
     
  30. $P1

    $P1 Ball State #1
    Staff Donor TMB OG
    Michigan WolverinesChicago CubsLos Angeles LakersChicago BearsChicago BlackhawksWest Ham UnitedBall State Cardinals

    We sent out a really fucking crafty one a few months ago that had about the same fail rate, including some in both IT and Operations senior leadership. Was right before summer and the subject was "Summer Flex PTO"...just impeccable timing.
     
    HuskerInMiami, fattus, ARCO and 11 others like this.
  31. dblplay1212

    dblplay1212 Well-Known Member
    Donor TMB OG
    Alabama Crimson TideNew York YankeesJacksonville Jaguars2pacSneakersFormula 1

    Thanks
     
  32. Tarpon Nole

    Tarpon Nole Well-Known Member
    Donor
    Florida State SeminolesTampa Bay RaysTampa Bay BuccaneersTampa Bay Lightning

    ~ taylor ~ and DuffandMuff like this.
  33. Prospector

    Prospector I am not a new member
    Donor
    Utah UtesArkansas Razorbacks

    $300 sounds pretty reasonable
     
  34. Tarpon Nole

    Tarpon Nole Well-Known Member
    Donor
    Florida State SeminolesTampa Bay RaysTampa Bay BuccaneersTampa Bay Lightning

    that’s per infected machine
     
    HuskerInMiami and angus like this.
  35. JGator1

    JGator1 I'm the Michael Jordan of the industry
    TMB OG
    Florida GatorsTampa Bay RaysTampa Bay BuccaneersTampa Bay LightningChelsea

  36. Tarpon Nole

    Tarpon Nole Well-Known Member
    Donor
    Florida State SeminolesTampa Bay RaysTampa Bay BuccaneersTampa Bay Lightning

    And the amount was meaningless. It wasn’t a ransomware attack. It was just built off an older ransomware attack. It was to shut down Ukrainian government
     
    Prospector likes this.
  37. Prospector

    Prospector I am not a new member
    Donor
    Utah UtesArkansas Razorbacks

    how big is the company, may still be a deal
    I really don't care, do you? I'm just shit posting while waiting on dinner
     
  38. Artoo

    Artoo 1312
    Donor

    Company IT got me with one of those. Coming out of COVID and they sent one out that looked legit enough talking about how it's been a tough year and they're giving everyone a free holiday ham, Click here to claim it.

    Of fucking course I clicked to claim a free ham, dammit!
     
  39. bertwing

    bertwing check out the nametag grandma
    Staff Donor
    Arkansas RazorbacksNew Orleans SaintsTiger WoodsBarAndGrill

    Suspect #1^^
     
  40. $P1

    $P1 Ball State #1
    Staff Donor TMB OG
    Michigan WolverinesChicago CubsLos Angeles LakersChicago BearsChicago BlackhawksWest Ham UnitedBall State Cardinals

    I'll DM you with a link proving my innocence
     
    ARCO, Jax Teller, One Two and 4 others like this.
  41. Bert Handsome

    Bert Handsome I'm sorry, the card says Moops
    Donor TMB OG
    Notre Dame Fighting IrishMilwaukee Brewers altMilwaukee BucksGreen Bay PackersTiger Woods

  42. bertwing

    bertwing check out the nametag grandma
    Staff Donor
    Arkansas RazorbacksNew Orleans SaintsTiger WoodsBarAndGrill

    I’m not falling for any more of your Barry dick pics pal
     
    BudKilmer likes this.
  43. Bert Handsome

    Bert Handsome I'm sorry, the card says Moops
    Donor TMB OG
    Notre Dame Fighting IrishMilwaukee Brewers altMilwaukee BucksGreen Bay PackersTiger Woods

    [​IMG]
     
    VaxRule likes this.
  44. GoodForAnother

    GoodForAnother the revolution will not be brought to you by Xerox
    Staff Donor TMB OG
    Kansas State WildcatsKansas City RoyalsKansas City ChiefsSporting Kansas CityTottenham HotspurBig 8 ConferenceBig 12 ConferenceCoors LightFormula 1

    oh yeah that one was a big deal, Zurich didn’t have a strong enough exclusion for cyber attacks, tried act of war because it was the best they had. ultimately they’re right that the property policy shouldn’t cover cyber attacks per se, but their form wasn’t clear and the tie always goes to the insured
     
  45. DuffandMuff

    DuffandMuff Well-Known Member
    Tampa Bay Lightning

    I finally fell for one of the test phishing emails our IT team sent out. Insanely deceiving. Now I simply don’t look at anything within an email. They’ll never get my response on a company survey or charity drive.
     
  46. Kirk Fogg

    Kirk Fogg "Tell them what they've won Olmec!"
    Donor TMB OG

    “how am I supposed to gamble my monthly SS, UAW pension, 401K, Coventry Direct Life Insurance buyout, and reverse mortgage?” - Arthur and Bertha yolo’ing in Vegas knowing they’ll be long dead before any of those systems collapse.
     
    TC, Prospector and Fat Drunk & Stupid like this.
  47. pnk$krtcrÿnästÿ

    Donor
    Rutgers Scarlet KnightsArizona WildcatsTexas AandM Aggies altTennessee Volunteers

    Good luck, IT dorks, I don't even check my work email.
     
  48. WC

    WC Bad Company, ‘til the day I die.
    Donor TMB OG
    North Carolina State WolfpackAtlanta BravesCarolina PanthersCarolina HurricanesUnited States Men's National Soccer Team

    The best time to start flipping ham was 20 years ago. The 2nd best time, is now!
     
  49. Born Again Lefty

    Born Again Lefty Respect The Pouch
    Donor TMB OG
    Miami Hurricanes

    Either opening a locked file, or the ransomware will auto display a message on the screen with contact information.

    Situation like this you call in Incident Response firms/FBI to negotiate. They are highly specialized and work to determine if they can recover through backups, find the decryption keys if it’s a a known ransomware (doubtful considering the scale of this) or they pay.

    Problem with paying is you A) don’t know if they’ll actually unlock anything B) If they also stole data you have to trust they don’t dump that information on the web after payment.

    Cyber insurance exists but it covers more than just the ransomware payment - those incident response firms, PR, legal, certain business losses, hardware if things get bricked after this, etc.
     
    DUCKMOUTH, fattus, Dump and 4 others like this.
  50. Cooler

    Cooler A mans gotta eat
    Donor
    Iowa HawkeyesChicago CubsChicago BearsUnited States Men's National Soccer Team

    All this. Have good backups and this isn’t really an issue. As long as the backups don’t also get encrypted. Otherwise it is usually impossible to recover the files. Companies usually end up paying bc they don’t backup enough or segregate it well enough and would lose too much critical data. Companies sometimes pay and still don’t get the data unencrypted. It’s a real shit situation.
     
    fattus, Dump, Josey Wales and 3 others like this.