packet.zip

Scattered Spider Members Indicted: Five Hackers Charged for MGM and Caesars Ransomware Attacks

Aamir Lakhani2 min read

Federal prosecutors have unsealed indictments against five alleged members of Scattered Spider, the cybercriminal group responsible for devastating ransomware attacks against MGM Resorts International and Caesars Entertainment in 2023. The charges include conspiracy, wire fraud, and identity theft. This marks one of the most significant cybercrime prosecutions in recent years targeting a Western-based, English-speaking threat group.

Scattered Spider, also tracked as UNC3944 and Octo Tempest, rose to infamy through a series of high-profile attacks using social engineering rather than technical exploits. The group specializes in calling corporate IT help desks, impersonating employees using personal data sourced from LinkedIn and data broker sites, and convincing help desk staff to reset multi-factor authentication. Once inside, they move laterally through hybrid Active Directory and Azure environments to deploy ransomware or exfiltrate data for extortion.

The MGM Resorts breach alone caused over $100 million in direct losses, disrupted hotel operations across Las Vegas for weeks, and exposed data on millions of guests. Caesars Entertainment quietly paid an estimated $15 million ransom. The group also targeted dozens of other organizations across retail, hospitality, and technology sectors in the US and UK. UK retailer Marks and Spencer and Co-op are among the most recent victims, having suffered attacks attributed to DragonForce affiliates using the Scattered Spider playbook.

Organizations most at risk are those with large hybrid workforces, outsourced IT help desks, and Entra ID or Okta-based identity platforms. Any company where a help desk agent can reset MFA over a phone call without strong out-of-band verification is vulnerable to the exact technique that enabled these attacks.

The indictments should not create a false sense that the threat has passed. CrowdStrike and others have documented that Scattered Spider's methodology has been absorbed by other RaaS affiliates who continue operating independently. Immediate defensive actions: remove help desk ability to reset MFA without video verification, enforce hardware token requirements for MFA resets, and audit all Entra ID Conditional Access policies for gaps that allow on-premises credential reuse in cloud environments.

These prosecutions represent the most direct accountability for a major ransomware operation in years, but the playbook these attackers pioneered has already spread far beyond any individual group.

Source: https://www.bleepingcomputer.com/news/security/scattered-spider-hackers-indicted-for-mgm-caesars-attacks/

Aamir Lakhani

Founder · Packet.Zip

Aamir Lakhani is a leading senior security strategist responsible for providing IT security solutions to major enterprises and government organizations. He creates technical security strategies and leads security implementation projects for

~/related

Keep digging

More research along the same attack path.

The Conference Recap Nobody Asked For But Everyone Needed

Check out my latest podcast with the famous TonyG around RSA: https://www.packet.zip/post/podcast-rsa-2026-recapSan Francisco's Moscone Center hosted (by what I could find online) 43,500 cybersecurity professionals last week. The one message I kept on hearing....AI...Agentic....Something....The con

Aamir Lakhani8 min read