MGM Resorts acknowledged a "cybersecurity issue" on 11 September 2023, though researchers and the attackers themselves place initial access several days earlier, around 8 September. What followed was the most publicly visible cyberattack in years, because its victims were on holiday and had cameras. Guests queued for manual check-in. Digital room keys stopped working. Slot machines sat dark across the floor. Restaurants wrote receipts by hand. For roughly nine days, until MGM declared operations restored companywide on 20 September, Las Vegas ran analog.

The intrusion is attributed by researchers to Scattered Spider — also tracked as UNC3944 and Octo Tempest — operating as an affiliate of the ALPHV/BlackCat ransomware-as-a-service operation. MGM has never named either in its filings, so the attribution rests on researcher analysis and the gang's own leak-site statements rather than company confirmation. The detail that made the story infamous belongs firmly in the claims column: relaying ALPHV's account, the researcher collective vx-underground said the crew found an MGM employee on LinkedIn and talked the IT help desk into handing over access in a roughly ten-minute phone call. MGM has never confirmed it. But the claim spread because it was plausible, and because it named the thing the industry had been under-defending for a decade.

The numbers came later. In an 8-K filed on 5 October, MGM estimated a roughly $100 million hit to third-quarter Adjusted Property EBITDAR, plus under $10 million in one-time costs — about $110 million all in. It said it did not pay a ransom, and disclosed theft of personal data on customers who transacted with MGM before March 2019, including driver's licence numbers and, for a limited number of people, Social Security or passport numbers.

Caesars Entertainment, hit in the same window, chose the other path. Its 8-K of 14 September blamed social engineering of an outsourced IT support vendor and confirmed theft of its loyalty-programme database. Press reports put its payment at roughly $15 million against a reported $30 million demand — figures Caesars has never confirmed. Two comparable companies, two opposite decisions, one month: an accidental natural experiment the industry has argued about ever since.

Also that month · The court in The Hague

The ICC calls it espionage

On 19 September, the International Criminal Court disclosed that it had detected anomalous activity on its systems during the previous week. In October it went further, characterising the incident as a targeted and sophisticated attack whose objective was espionage. No attribution has been officially confirmed. The context was impossible to ignore: the breach landed months after the court issued an arrest warrant for Vladimir Putin and Russia opened criminal proceedings against ICC officials. France publicly condemned the attack. An institution whose entire function is holding evidence about the powerful had become, predictably, a target of the powerful.

Also that month · The claim that unravelled

RansomedVC versus the facts

On 25 September, the extortion group RansomedVC claimed to have compromised "all of Sony systems", offered roughly 260 GB for sale and posted about 6,000 files as proof. Sony said only that it was investigating. The claim collapsed under scrutiny — the sample was far too thin to support it — and then a rival actor calling itself MajorNelson publicly accused RansomedVC of lying for clout and dumped the same data for free. The episode is a useful antidote to a habit this archive tries to avoid: treating leak-site posts as journalism. Extortion brands compete for attention, and inflated claims are a marketing expense. (Sony did confirm a genuine, unrelated MOVEit-linked breach affecting roughly 6,800 people.)

India desk · September 2023

DDoS on the eve of the G20

On the evening of 7 September 2023, the Delhi Police and Mumbai Police websites were knocked offline by denial-of-service attacks — two days before world leaders arrived in New Delhi for the G20 summit. The hacktivist group Team Insane PK claimed responsibility, continuing a campaign against Indian targets it had run since early that year. The government had already raised alert levels around critical infrastructure and imposed a zero-trust posture on summit systems, and India's I4C later stated that the official G20 website faced sustained pressure peaking at roughly 1.6 million intrusion attempts per minute across the 9–10 September summit, repelled by a coordinated national response — a figure disclosed in January 2024 rather than at the time. Later in the month, a group calling itself Indian Cyber Force claimed DDoS attacks on Canadian government-linked sites amid the diplomatic row over the killing of Hardeep Singh Nijjar; Ottawa said core federal infrastructure was untouched, and the group has no formal link to New Delhi. Hacktivism, in both directions, had become a standard feature of Indian diplomatic friction.

⏳ Time capsule — September 2023

  • Apple's "Wonderlust" event on 12 September introduced the iPhone 15, replacing Lightning with USB-C after eleven years.
  • The Writers Guild of America strike formally ended on 27 September after 148 days.
  • A magnitude 6.8 earthquake struck Morocco's High Atlas mountains on 8 September, killing roughly 2,900 people.
  • Novak Djokovic won a record-equalling 24th Grand Slam singles title at the US Open on 10 September.
Where it stands today — 2026

The phone call that changed procurement

MGM and Caesars turned help-desk identity verification from a compliance checkbox into a board-level control, and made Scattered Spider the most-studied threat cluster of the decade — a crew that would go on to empty British retail shelves in 2025 and reach airlines and insurers after that. The pay/don't-pay split between the two casinos is still cited in every ransomware tabletop exercise, without a settled verdict. And the September 2023 lesson has only hardened with the years documented elsewhere in this archive: from Clorox's help desk a month earlier to the 2025 lawsuits that followed, the softest interface in any organisation remains a human being who wants to be helpful, on a phone, with the power to reset a password.