iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
The September 2023 cyberattacks involving MGM Resorts and Caesars Entertainment were linked in reporting to Scattered Spider and ALPHV/BlackCat, but the available accounts did not establish that the same group carried out both attacks. Caesars disclosed a social-engineering attack on an outsourced IT support vendor and theft of loyalty-program data. Claims about MGM conflicted, so attribution there remains qualified.
Which Las Vegas cyberattacks are at issue?
The incidents were cyberattacks affecting MGM Resorts and Caesars Entertainment, casino operators with Las Vegas properties, in September 2023. MGM experienced reported disruption to payments, reservation sites, ATMs, room-key systems and casino services as it worked to recover. Those were reported effects during the incident, not a description of current conditions. TechCrunch’s September 14, 2023 report covered the disruption and the claims then being made about MGM.
Who was linked to the attacks?
Scattered Spider
Scattered Spider is the name used by government agencies and cybersecurity researchers for a financially motivated hacking group. In a November 16, 2023 advisory, the FBI and CISA said its actors typically use social engineering to steal data for extortion and had recently leveraged BlackCat/ALPHV ransomware. The agencies’ advisory describes the group’s tactics and activity.
ALPHV/BlackCat
ALPHV, also known as BlackCat, is a ransomware operation—not another name for Scattered Spider. In reporting on MGM, both a person claiming to represent Scattered Spider and ALPHV claimed responsibility. That overlap does not establish whether there was an affiliate relationship, shared membership, or competing claims.
#1 Best Overall
What is known about each company’s incident?
Caesars: vendor-targeted social engineering and stolen loyalty data
Caesars said suspicious activity on its IT network resulted from a social-engineering attack on an outsourced IT support vendor. The attackers obtained a copy of information from the company’s loyalty-program database, including driver’s license and/or Social Security numbers for a significant number of members. TechCrunch reported that Caesars said it had taken steps to secure deletion of the stolen data but could not guarantee that it had been deleted.
A person claiming to represent Scattered Spider denied involvement in the Caesars incident, according to CyberScoop’s September 14, 2023 coverage. Caesars’ disclosure establishes the reported entry path and data theft; it does not settle who was behind the attack.
MGM: operational disruption and conflicting claims
MGM’s reported outages affected multiple customer-facing and casino systems. A Scattered Spider representative claimed responsibility, while ALPHV also claimed the attack. Contemporary reporting said the exact perpetrators were unclear, and the available accounts did not independently resolve the claims or establish what data MGM attackers exfiltrated. The claims should therefore be treated as claims, not as definitive attribution.
Are Scattered Spider and ALPHV the same group?
No. The FBI and CISA described Scattered Spider as having recently leveraged BlackCat/ALPHV ransomware, which indicates use of a ransomware operation’s tools; it does not make the groups synonymous. Reporting at the time left their precise relationship uncertain. Scattered Spider could have used ALPHV’s ransomware through an affiliate arrangement, or the overlap in claims could have reflected shared members or competing accounts. The evidence cited in the contemporaneous reports does not decide among those possibilities.
Rank #3
Why are the groups described as prolific?
A July 1, 2026 U.S. Department of Justice announcement said a criminal complaint alleges Scattered Spider was involved in more than 100 network intrusions, with more than $100 million in ransom payments and millions of dollars in victim damages. These are allegations about the group’s activity overall, not a count or loss estimate for the MGM and Caesars incidents, and they are not presented as findings after trial. The DOJ announcement also lists Octo Tempest, UNC3944 and 0ktapus as other names used in the complaint’s description of Scattered Spider. Read the DOJ announcement for the scope of those allegations.
The figures give scale to the allegations, but they do not establish a comparative ranking of Scattered Spider against other criminal groups, nor do they prove who carried out either Las Vegas incident.
Quick Recap
Best Value
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

