On September 23, 2026, MGM Resorts International, a global leader in hospitality and entertainment, announced it had identified a cyberattack within its technology environment. In response, the company took immediate containment measures by shutting down certain computer systems. This proactive step has led to operational disruptions, though the full extent is not yet public. The company is currently investigating the incident with the assistance of cybersecurity experts. The identity of the attackers and the scope of any potential data exfiltration remain unknown at this time.
The incident at MGM Resorts is a developing cyberattack with limited public information. The company's decision to shut down systems indicates a serious event, likely aimed at preventing the spread of malware, such as ransomware, or stopping active data exfiltration. The initial access vector and the specific systems affected have not been disclosed. Such attacks on hospitality giants are often financially motivated, targeting payment systems, customer databases containing personal information and loyalty program data, or aiming for wide-scale disruption via ransomware.
While details are unconfirmed, attacks on large enterprises like MGM often follow a common pattern involving credential theft, lateral movement, and data encryption or exfiltration. Based on typical TTPs used in such incidents, the attack may have involved:
The shutdown of systems at a company of MGM's scale can have cascading operational and financial impacts:
No specific Indicators of Compromise (IOCs) are available at this time.
Security teams at similar organizations can hunt for precursor activity. The following patterns could indicate related activity:
powershell.exe, psexec.exe, wmic.exeMGM's immediate response to shut down systems is a key part of the 'Evict' phase of incident response.
D3-PA - Process Analysis.D3-NI - Network Isolation and D3-FR - File Restoration.To prevent similar attacks, hospitality organizations should prioritize:
Protects against the use of stolen credentials, a common vector in major breaches.
Limits the blast radius of an attack, preventing attackers from moving from less sensitive systems to critical ones.
Enables detection of anomalous activity through comprehensive logging and monitoring.
Patching vulnerabilities is crucial to prevent initial access and lateral movement.
In a complex environment like MGM Resorts, Network Isolation (segmentation) is a critical proactive and reactive control. Proactively, guest-facing networks (Wi-Fi), corporate IT networks (employee workstations, email), and operational systems (property management, payment processing, gaming floors) must be strictly segregated. Firewalls between these segments should enforce a default-deny policy, only allowing explicitly required traffic. Reactively, as demonstrated by MGM, the ability to quickly isolate affected segments or the entire network is crucial for containment. This prevents ransomware from spreading or attackers from pivoting to other parts of the business. An effective segmentation strategy would mean a compromise on the corporate network could not easily traverse to the point-of-sale systems, limiting the immediate financial and data breach impact.
For a business like MGM that relies on constant system availability, a robust File Restoration capability is non-negotiable. This goes beyond simple backups. Organizations must implement the 3-2-1 rule (3 copies, 2 different media, 1 offsite/offline). One of these copies should be immutable or air-gapped, meaning attackers who gain administrative access to the network cannot delete or encrypt it. In the context of the MGM attack, having tested, immutable backups of their reservation systems, customer databases, and property management systems is the key to recovery. It allows the organization to restore operations without considering a ransom payment, significantly reducing the attacker's leverage. Regular, automated testing of these backups is essential to ensure they are viable when a real incident occurs.
Process Analysis, typically performed by an Endpoint Detection and Response (EDR) solution, is vital for detecting attacks before they reach the impact stage. In an environment like MGM's, an EDR agent should be deployed on all endpoints and servers, including those running point-of-sale and property management software. The EDR tool should be configured to detect and alert on common attacker behaviors, such as a non-IT process like winword.exe spawning a powershell.exe shell, or lsass.exe memory being dumped to disk (a credential theft technique). By analyzing process parent-child relationships and command-line arguments, security teams can spot the abuse of legitimate tools for malicious purposes, providing an early warning that an attacker is active in the network and allowing for intervention before systems are encrypted or data is stolen.
MGM Resorts International identifies a cyberattack and shuts down some systems to contain it.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.