MGM Resorts and Caesars Entertainment were hit in closely timed cyberattacks that investigators and security firms tied to the Scattered Spider criminal community, a loose English-speaking group known for social engineering, SIM swapping, phishing, and MFA fatigue. Caesars disclosed that attackers stole customer data and reportedly paid a ransom demand, while MGM suffered a far more disruptive intrusion that knocked hotel and casino operations offline for days and was later estimated to have cost about $100 million. Multiple reports said the intrusions involved help-desk impersonation and other employee-targeting tactics, with Scattered Spider affiliates also linked to ransomware operators including BlackCat/ALPHV.
The fallout expanded beyond the initial breaches as Caesars sent breach notifications to thousands of affected people and both casino companies faced lawsuits and class actions alleging failures to protect personal information. Law enforcement pressure then intensified: investigators in the US, UK, and Spain pursued suspected Scattered Spider members, including a 22-year-old British man arrested in Spain as an alleged leader and a 17-year-old arrested in the UK over the MGM attack, with additional US arrests and prosecutors reportedly moving closer to charges. Security researchers said the Las Vegas casino intrusions put a bullseye on the group, which had evolved from SIM-swapping into ransomware, extortion, and cloud-focused intrusions against major enterprises.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
14 events from the most recent confirmed update back to the earliest known activity.
A September 2025 report said a teen hacker had been arrested in connection with the 2023 Las Vegas casino cyberattack. This indicated the investigation continued well beyond the initial 2024 arrests.
UK authorities arrested a 17-year-old boy from Walsall in coordination with the FBI on suspicion of blackmail and Computer Misuse Act offenses tied to the 2023 MGM Resorts ransomware attack. He was later released on bail while the broader investigation continued.
On June 17, 2024, media reports detailed the Spain arrest and framed it as part of a broader international crackdown following attacks on MGM Resorts, Caesars Entertainment, and other major companies. The reporting also highlighted the group's evolution from SIM swapping to ransomware and extortion.
Spanish authorities arrested a 22-year-old British man at Palma Airport on suspicion that he was a leading Scattered Spider figure. Authorities said the arrest occurred on May 31 under an international warrant tied to attacks on dozens of US companies.
Mandiant CTO Charles Carmakal said the Las Vegas casino intrusions, especially the MGM attack, put a bullseye on Scattered Spider and accelerated law-enforcement attention. He added that some arrests had already occurred and prosecutors were getting closer to charges.
Caesars began notifying thousands of individuals that their personal information had been compromised in the breach. The notifications expanded public understanding of the scale of the customer-data exposure.
By late September 2023, complaints and class actions had been filed alleging MGM Resorts and Caesars Entertainment failed to protect personal information exposed in the cyberattacks. The legal actions marked a new phase of fallout from the incidents.
Mid-September 2023 coverage increasingly attributed the MGM Resorts and Caesars incidents to the loosely organized Scattered Spider community, often described as young English-speaking social engineers working with ransomware affiliates such as ALPHV/BlackCat.
Caesars Entertainment publicly confirmed that attackers stole customer data and that the company paid the extortion demand. The disclosure established Caesars as a confirmed victim in the Las Vegas casino cybercrime spree.
Attackers linked in later reporting to Scattered Spider breached Caesars Entertainment in 2023 by reportedly tricking or socially engineering IT support. Customer data was stolen during the intrusion.
Multiple September 2023 reports said Caesars paid a ransom demand following the theft of customer data. The payment was widely reported as occurring before Caesars publicly confirmed details of the incident.
MGM Resorts was hit by a cyberattack in September 2023 that severely disrupted hotel and casino systems for about a week. Later reporting linked the intrusion to actors associated with Scattered Spider and ransomware/extortion activity.
Spanish authorities later said their investigation into a suspected Scattered Spider leader began in May 2023 after the FBI's Los Angeles office requested information. This marked an early law-enforcement probe tied to the group later linked to the Las Vegas casino intrusions.
Reporting in June 2024 referenced a prior January arrest in Florida of suspected Scattered Spider affiliate Noah Urban. The arrest signaled growing US law-enforcement action against people tied to the group.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
14 references tracked. Mallory keeps watching after this page renders.
usatoday.com
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourcetheregister.com
Open sourcethecyberexpress.com
Open sourceqz.com
Open sourcebleepingcomputer.com
Open sourcefoxbusiness.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.