{"id":355,"date":"2025-04-23T14:10:55","date_gmt":"2025-04-23T14:10:55","guid":{"rendered":"https:\/\/sites.wp.odu.edu\/aurorafrancis\/?p=355"},"modified":"2025-04-23T14:10:55","modified_gmt":"2025-04-23T14:10:55","slug":"research-paper-1","status":"publish","type":"post","link":"https:\/\/sites.wp.odu.edu\/aurorafrancis\/2025\/04\/23\/research-paper-1\/","title":{"rendered":"Research Paper 1"},"content":{"rendered":"\n<p>What Happened?<\/p>\n\n\n\n<p><br>It all began in September of 2023, when the Casino Resort MGM discovered a security<br>breach where a third party obtained personal customer information including phone numbers,<br>driver\u2019s license information, and for some even social security information. A group of hackers<br>called Scattered Spider took credit for the breach. It is believed that they accessed the MGM<br>systems by using phishing techniques to acquire employee login credentials and then use that<br>information to login to the system. Once into the system they reset the multifactor authentication<br>(MFA) and added an identity provider (IdP) to MGM\u2019s network allowing them to increase their<br>control over the network and access their cloud assets (Thompson 2023).<\/p>\n\n\n\n<p><br>Vulnerabilities &amp; Repercussions<\/p>\n\n\n\n<p><br>This attack exposes the vulnerabilities of \u201cthe human factor\u201d of cybersecurity with the<br>employees being prone to these phishing attacks, likely due to a lack of training against it.<br>MGM\u2019s failure to detect the MFA reset is also a notable issue because if it had been detected<br>they could have mitigated loss or even limited the attacker\u2019s access. The attack in the system<br>caused ATM\u2019s and slot machines to not operate, guest suite cards and key cards to not work,<br>electronic payments were not working and some TV and phone lines to go down causing the<br>casino to close down many operations for days. The result of this attack was the loss of millions<br>of dollars from MGM every day.<\/p>\n\n\n\n<p><br>Mitigation Tactics<\/p>\n\n\n\n<p><br>Ways MGM could mitigate these issues in the future are monitoring their MFA systems<br>and if that system is via third party, establish higher cybersecurity standards. Another way to<br>mitigate is by having intrusion detection systems and incident response plans (Convocar 2023). These plans can include keeping backups be it physically or on a separate system so in the case<br>of an incident or breach the system can quickly recover. Also ensuring that the backups are<br>updated regularly and that the systems both hardware and software are up to date.<\/p>\n\n\n\n<p><br>References<\/p>\n\n\n\n<p><br>Convocar, Jessa Mikka. \u201cWhat You Can Learn from the 2023 MGM Las Vegas Cyber-Attack.\u201d<br>Intelligent Technical Solutions, Intelligent Technical Solutions, 4 Oct. 2023,<br>www.itsasap.com\/blog\/mgm-ransomware-attack-takeaways.<br>Thompson, Andy. \u201cThe MGM Resorts Attack: Initial Analysis.\u201d Identity Security and Access<br>Management Leader, 16 Nov. 2023, www.cyberark.com\/resources\/blog\/the-mgm-resorts-<br>attack-initial-analysis.<br>Siddiqui, Zeba. \u201cCasino Giant MGM Expects $100 Million Hit from Hack That Led to Data &#8230;\u201d<br>Reuters, 5 Oct. 2023, www.reuters.com\/business\/mgm-expects-cybersecurity-issue-<br>negatively-impact-third-quarter-earnings-2023-10-05\/.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>What Happened? It all began in September of 2023, when the Casino Resort MGM discovered a securitybreach where a third party obtained personal customer information including phone numbers,driver\u2019s license information, and for some even social security information. A group of hackerscalled Scattered Spider took credit for the breach. It is believed that they accessed the&#8230; <\/p>\n<div class=\"link-more\"><a href=\"https:\/\/sites.wp.odu.edu\/aurorafrancis\/2025\/04\/23\/research-paper-1\/\">Read More<\/a><\/div>\n","protected":false},"author":27605,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wds_primary_category":14},"categories":[14],"tags":[16,15],"_links":{"self":[{"href":"https:\/\/sites.wp.odu.edu\/aurorafrancis\/wp-json\/wp\/v2\/posts\/355"}],"collection":[{"href":"https:\/\/sites.wp.odu.edu\/aurorafrancis\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sites.wp.odu.edu\/aurorafrancis\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/aurorafrancis\/wp-json\/wp\/v2\/users\/27605"}],"replies":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/aurorafrancis\/wp-json\/wp\/v2\/comments?post=355"}],"version-history":[{"count":1,"href":"https:\/\/sites.wp.odu.edu\/aurorafrancis\/wp-json\/wp\/v2\/posts\/355\/revisions"}],"predecessor-version":[{"id":356,"href":"https:\/\/sites.wp.odu.edu\/aurorafrancis\/wp-json\/wp\/v2\/posts\/355\/revisions\/356"}],"wp:attachment":[{"href":"https:\/\/sites.wp.odu.edu\/aurorafrancis\/wp-json\/wp\/v2\/media?parent=355"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/aurorafrancis\/wp-json\/wp\/v2\/categories?post=355"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/aurorafrancis\/wp-json\/wp\/v2\/tags?post=355"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}