MGM Casino $100M CYBER ATTACK - What Your Business Can Learn From It

April 30, 2024

MGM Casino’s $100M Cyber Attack: What Your Business Can Learn About Cyber Liability Insurance

In September 2023, MGM Resorts International—one of the largest and most technologically advanced casino operators in the world—fell victim to a cyberattack that resulted in losses of over $100 million. If a business with this level of investment in IT security can be compromised, what does that mean for the average small to mid-sized business?


NBC News Article: MGM Cyberattack Cost $100M


Let’s break down what happened and what key takeaways your business can learn to protect against similar incidents.


What Happened to MGM?

The attackers didn’t rely on sophisticated malware or brute-force hacking. Instead, they used social engineering—specifically, a phone call to MGM's IT helpdesk. By impersonating an employee, they convinced support staff to bypass the Multi-Factor Authentication (MFA) system, giving them unauthorized access to MGM’s internal systems.


The simplicity of the breach is what makes it so alarming. Despite layers of advanced cybersecurity technology, human error was the weak link.


Why Cybersecurity Spending Alone Isn’t Enough

MGM spends tens of millions annually on its cybersecurity infrastructure. And yet, a single successful phishing-style call caused a massive operational shutdown across multiple casinos, delayed hotel check-ins, and took down slot machines and payment systems.


The reality is that 90% of cyber incidents involve human error—not technological failure.

This is a reminder that cybersecurity must include employee training, internal protocols, and risk transfer tools like insurance.


3 Key Lessons for Business Owners


1. Even the Best Systems Can Fail

No business is immune. You might have a firewall, antivirus software, and MFA in place—but human factors can still bypass all of them.


2. Cyber Liability Insurance Is a Critical Safety Net

When prevention fails, cyber insurance steps in to cover the fallout—business interruption losses, legal fees, forensic investigations, notification costs, and even ransom payments. Without insurance, a major breach could financially devastate your business.


3. Employee Awareness Is Your First Line of Defense

Train your team to spot phishing, avoid sharing sensitive data over the phone, and report suspicious activity immediately. A single uninformed action can have multimillion-dollar consequences.


Final Thoughts

The MGM cyberattack wasn’t just a blow to one of the world’s most recognizable brands—it was a wake-up call to every business that no amount of security spend can fully eliminate cyber risk.

If MGM can be hit, so can you. That’s why cyber liability insurance isn’t just optional—it’s essential to any serious business risk management plan.


Need help reviewing your cyber insurance coverage?


📞 We’re here to help. Contact us today to make sure your business is protected.

Contact Us

What Does Professional Liability Insurance (E&O Insurance) Cover?
By Bryan Gutowsky July 22, 2024
Wondering what professional liability insurance covers? Learn how E&O insurance protects businesses like consultants, architects, and IT professionals from costly lawsuits, legal fees, and client claims.
Is Cyber Insurance Mandatory? | Cyber Liability 101
By Bryan Gutowsky July 20, 2024
Cyber insurance isn’t legally required in 2024, but it's becoming a must-have for protecting your business from growing cyber threats. Learn what it covers and why it matters.
What Is Uninsured & Underinsured Motorist Coverage in Michigan?
By Bryan Gutowsky July 18, 2024
Learn why uninsured and underinsured motorist coverage is a must-have in Michigan. Discover what it covers, how it protects you after an accident, and why you should add it to your auto insurance policy.
What Does Tech E&O Insurance Cover?
By Bryan Gutowsky July 17, 2024
What does Tech E&O insurance cover? Learn how Technology Errors and Omissions Insurance protects tech businesses from negligence claims, cyber risks, and client financial losses.
What Is a Retroactive Date in Commercial Insurance?
By Bryan Gutowsky July 16, 2024
Confused about retroactive dates in insurance? Learn what a retroactive date is, why it matters, and how it affects coverage in claims-made policies like E&O, Directors & Officers coverage, and EPLI.
Does Cyber Insurance Cover Ransom Payments? Cyber Liability 101
By Bryan Gutowsky July 15, 2024
Wondering if cyber insurance covers ransomware attacks and ransom payments? Learn how cyber liability policies can protect your business from the financial and operational impact of a ransomware incident.
MI Workers Comp: Minimum Coverage Requirements (Why You May Want More)
By Bryan Gutowsky July 13, 2024
Learn Michigan’s workers’ compensation minimum coverage limits and why upgrading to higher limits—like $500K or $1M—can better protect your business and employees.
PLPD vs Full Coverage – What’s the Difference? MI Auto Insurance
By Bryan Gutowsky July 10, 2024
Confused about the difference between PLPD and full coverage in Michigan? Learn what each covers, when you might need one over the other, and how to choose the right auto insurance for your situation.
How To Comply With Cisco’s Insurance Requirements? (Basic Guide)
By Bryan Gutowsky July 9, 2024
Looking to partner with Cisco? Learn how to meet Cisco’s insurance requirements, including general liability, workers comp, cyber insurance, and professional liability. A simple guide for compliance.
Michigan Homeowners Insurance: Everything You Need to Know
By Bryan Gutowsky July 8, 2024
Learn everything you need to know about homeowners insurance in Michigan, including key coverages, optional riders, discounts, and common mistakes to avoid.
Show More