Alleged mastermind of MGM hacking group arrested in Spain

The alleged mastermind of the group that hacked MGM Resorts last Autumn was arrested in a joint Spanish-FBI operation on 31 May.

The 22-year-old British national (pictured), allegedly the head of the Scattered Spider ransomware group, was arrested by Spain’s National Police at Palma airport attempting to board a flight to Naples.

The group were allegedly behind the September 2023 cyberattack at MGM Resorts, in which hackers breached the operator’s systems and demanded payment.

On advice from US government entities, MGM chose not to pay the ransom demanded by the hacking group.

The incident, which led to outages at everything from slot machines to digital key cards, led to a $100m EBITDA hit to its Q3 results.

Scattered Spider are said to have obtained 391 bitcoins worth over $27m through their activities, which involved stealing information from businesses.

The National Police outlined that the group’s modus operandi consisted of using phishing techniques against individuals to access credentials that were then used to steal sensitive information or cryptocurrencies.

The investigation: National Police locate alleged hacker

The investigation began in May 2023 when the FBI Los Angeles Office, through its Spanish liaison, requested information about a British citizen who they suspected could be in the country.

The individual was allegedly responsible for numerous computer attacks at multiple companies in the US.

The Spanish side of the investigation was carried out by the National Police’s Central Cybercrime Unit in collaboration with agents from the Balearic Superior Headquarters.

The police said they made efforts to locate the alleged hacker from the moment they received tipoffs. They confirmed by the end of the month that he had entered Spain through Barcelona’s El Prat airport.

The FBI then reported that an international arrest warrant had been issued against the individual by the California Central District Court.

The Bureau has been cracking down on the hacking group in the months following the cyberattack.

This resulted in an intensifying of investigative efforts, with police ultimately confirming he was in Palma de Mallorca, Spain.

When arrested, the alleged mastermind was carrying a laptop and a mobile phone that were seized.

A Spanish judge subsequently ordered him to be placed in a provisional prison.

MGM is still being affected by the fallout from the September incident and is facing an ongoing FTC probe into the adequacy of its data security practices.

The Las Vegas-tentpole is attempting to fight the probe in the courts, with the FTC opting to counter sue this week to enforce compliance with its investigative demands.

The company has also been hit by multiple class action suits related to the cyberattack, highlighting harms caused by the stolen personal information.

Multiple US casino cyberattacks

MGM is not the only US casino hacked in recent months.

The business’ Las Vegas and OSB competitor Caesars Entertainment also saw its systems breached, but reportedly chose to pay the ransom.

This week, Nevada casino operator Olympia Gaming has stated that it has been the victim of a hacking incident.

Hackers, using phishing techniques, were able to obtain customer information including credit card numbers and addresses.

Olympia Gaming CEO Michael Stone said at a press conference: “We are deeply regretful that this breach has occurred and are doing everything in our power to protect our customers and their information.

“We are taking this matter very seriously and are working around the clock to rectify the situation.”