Part III: Slot Machine Cheating · Electronic & Digital Cheating Methods
SCAM #15: Ransomware Attack on Gaming Operations (Scattered Spider Method)
How it works
The Scattered Spider / ALPHV attack on MGM Resorts in September 2023 demonstrated how ransomware can directly impact slot machine operations. The attack began with social engineering (vishing) to obtain credentials, escalated to full network access, and culminated in ransomware deployment across approximately 100 ESXi hypervisors hosting thousands of virtual machines. This shut down critical systems including slot machines (which displayed error messages), ATMs, digital room keys, reservation systems, and websites. While the primary motive was data theft extortion rather than direct slot cheating, the same attack vector could be used to manipulate gaming systems if attackers gained sufficient access. A sophisticated attacker with CMS access could theoretically alter progressive jackpot configurations, change payout percentages, or create phantom player accounts to launder money.
Where it appears
All casino digital infrastructure — slot machines, CMS servers, player tracking systems, financial systems, hotel operations, ATMs, online gaming platforms
On the record
The September 2023 MGM Resorts attack by Scattered Spider (working with ALPHV/BlackCat ransomware) caused approximately $100 million in losses. Attackers used LinkedIn to identify an employee, then called MGM’s IT help desk to obtain credentials. The attack disrupted operations for approximately 10 days. Caesars Entertainment was hit by a similar attack around the same time and reportedly paid $15 million of a $30 million ransom demand. In July 2024, a 17-year-old from the UK was arrested in connection with the MGM hack.
Published as a detection reference for surveillance, compliance and gaming-operations professionals. Thresholds and tuning are set by the property. Nothing here is instruction — the method is described so it can be recognised.