A teenage boy suspected of participating in the 2023 cyberattacks on Las Vegas's two largest casino companies has surrendered to authorities. He faces six felony charges, including identity theft, extortion, and unlawful computer acts. Prosecutors are seeking to try him as an adult due to the severity of the offenses.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
A judge later ordered the teenage suspect released to parental custody while the casino cyberattack case proceeds. This marked a change in the suspect's legal status after the earlier detention and indictment.
Following the surrender, reporting said the suspect was indicted and detained in connection with the 2023 casino cyberattacks. Coverage identified the case as involving alleged Scattered Spider activity targeting Las Vegas casinos.
Canadian authorities dismantled the TradeOgre cryptocurrency exchange and seized roughly $40 million in crypto assets. The enforcement action was reported as a distinct law-enforcement development separate from the Las Vegas casino case.
A teenage suspect accused in the 2023 Las Vegas casino intrusions surrendered to authorities in September 2025. Multiple reports describe the suspect as an alleged Scattered Spider member tied to the casino network attacks.
In 2023, major cyberattacks hit Las Vegas casino operators, including MGM Resorts and Caesars Entertainment, and were later linked by reporting to the Scattered Spider threat group. The incidents became the basis for subsequent criminal investigations and charges against a teenage suspect.
8 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcedatabreaches.net
Open sourcescworld.com
Open sourcesecurityaffairs.com
Open sourcego.theregister.com
Open sourcecyberscoop.com
Open sourcebleepingcomputer.com
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.