• Subscribe
  • Magazines
  • About
  • Contact
  • Advertise
Monday 12 May 2025
  • zh-hant 中文
  • ja 日本語
  • en English
IAG
Advertisement
  • Newsfeed
  • Mag Articles
  • Video
  • Opinion
  • Tags
  • Regional
    • Africa
    • Australia
    • Cambodia
    • China
    • CNMI
    • Europe
    • Hong Kong
    • India
    • Japan
    • Laos
    • Latin America
    • Malaysia
    • Macau
    • Nepal
    • New Zealand
    • North America
    • North Korea
    • Philippines
    • Russia
    • Singapore
    • South Korea
    • Sri Lanka
    • Thailand
    • UAE
    • Vietnam
  • Events
  • Contributors
  • SUBSCRIBE FREE
No Result
View All Result
IAG
  • Newsfeed
  • Mag Articles
  • Video
  • Opinion
  • Tags
  • Regional
    • Africa
    • Australia
    • Cambodia
    • China
    • CNMI
    • Europe
    • Hong Kong
    • India
    • Japan
    • Laos
    • Latin America
    • Malaysia
    • Macau
    • Nepal
    • New Zealand
    • North America
    • North Korea
    • Philippines
    • Russia
    • Singapore
    • South Korea
    • Sri Lanka
    • Thailand
    • UAE
    • Vietnam
  • Events
  • Contributors
  • SUBSCRIBE FREE
No Result
View All Result
IAG
No Result
View All Result

OPINION: The MGM Resorts casino hack … where was the regulator?

David Green by David Green
Sun 12 Nov 2023 at 23:09
MGM Resorts to acquire remaining 50% CityCenter stake, sell to Blackstone
32
SHARES
800
VIEWS
Print Friendly, PDF & Email

The hacking of MGM Resorts’ computer and data storage systems in September last reportedly cost the group around US$100 million in EBITDAR, according to its SEC filing dated October 5, 2023. Having personally experienced the impact of the cyberattack, I believe it would have suffered even greater losses, but for the apparent slow response of its casino regulator, the Gaming Control Board. Let me explain.

I checked into MGM’s Aria property on the Las Vegas strip on 12 September, having stayed there, without incident, a week earlier. While travelling from Utah back to the property, I heard a radio report that Strip properties operated by MGM has been the target of a large scale cyberattack. It came as no surprise, therefore, that check-in was chaotic, as staff had to complete formalities manually. Clearly additional personnel had been drafted in to deal with reams of computer printouts containing reservation details, which had to be consulted and cross-checked with customer ID. Quite an undertaking for a property with around 4000 rooms! In the circumstances the front desk folk could not be faulted for their performance.

On walking through the casino to the elevators (which incidentally were staffed by employees to mitigate the risk of patrons being stuck in them), ATMs and machines and tables all appeared to be functioning normally. This was a contrast with the hotel’s bars which by that time were cash only, and no room charges. Several hours later, while sat at a bar adjacent to the gaming floor, I noticed a number of people sitting at machines with tower lights illuminated, apparently waiting for a machine re-set or a hand-pay. To get a better appreciation of what was happening, I played a 10c TITO machine, cashing out, or rather attempting to when I had a small win. No ticket was forthcoming. The tower light illuminated so I sat waiting for an attendant to hand-pay my winnings (about US$50).

After 20 minutes, nearby patrons told me I would likely be waiting two to three hours as there was only one attendant known to be servicing the entire floor.

Had I won say US$5000 and had a spare two to three hours, I would likely have waited around. In fact someone had won US$2,500, a problematic amount considering tax needs to be withheld on wins of US$1,200 or more and the win reported to the IRS. Another player had won US$600 but had a work commitment which made it impossible for him to wait for such an extended period for his pay-out. Like me, he did not have an MGM Player card, and even if he did, there could be no certainty that it had recorded his play.

Returning to the scene some two hours later after dinner, it appeared that all machines on the floor had been shut down. The machine I had played had been cleared, raising the question as to how I could claim my winnings. I had no evidence that I had won; no screenshot, no player card, and no third party record of it. Unlike the two other winners I mentioned previously, my win was immaterial, but it did set me thinking … where was the Gaming Control Board (GCB) while this was going on?

Later that evening I sent an email to GCB asking why MGM had continued to operate its slot machines. By the time I played the machine in question, MGM must have known that the TITO system was not functioning, either reliably or, more likely, at all. I put the following to the GCB:

“If MGM Resorts knew, or should have known that its machines could not issue tickets for winnings, why was it allowed to continue to operate its gaming machines? To me, it is an egregious violation of the rules and /or spirit of game fairness… Where was GCB in all of this?”

The next day, I received a response to the effect that the attack on MGM Resorts was unprecedented, and that the GCB was working with the company to remedy the situation.

With respect to the GCB, cyberattacks are hardly “unprecedented”; in fact, they are a pervasive business risk, the likelihood and severity of which many corporates have under-estimated to their great cost, both monetary and reputational. Any risk and Audit Committee of a listed corporation which does not have this risk at or near the top of its list is not doing its job.

I replied to GCB, not wishing to let it off the hook quite so readily when it came to machines that had been cleared with money still owed to players:

“How does MGM propose to track and reimburse them, when there is no record that I am aware of as to who won what? Taking photos is obviously not an option; apart from re-visiting the gaming floor and physically identifying a machine which registered a win, how else does the company propose to identify players owed winnings…through surveillance? To me, the bottom line is that the machines should never have been allowed to operate until the precise nature of the risk and its impact had been determined. It is interesting that many of the machines on the floor were turned off later the same evening. Rather too late for many.”

I received no response. Perhaps that is understandable; the State of Nevada collects tax on the gross gaming revenue of its licensees, and even at 6.75% that gives it a real interest in seeing GGR maximised. According to the Nevada Department of Taxation, MGM Resorts is by a considerable margin the largest taxpayer in Nevada.

Most players are likely vacationers or convention delegates from out of State or country, so why should GCB concern itself and deploy resources to monitor and direct how those people are identified and compensated?

The obvious rejoinder is, because that is its role! It should be protecting players, given that is an essential underpinning of the Nevada gaming law. I attribute no malice to anyone involved, just complacency and under-preparedness.

RelatedPosts

China-owned contractor of Chow Tai Fook’s Baha Mar ordered to pay US$1.6 billion to original owner for “many acts of fraud”

New York appellate court dismisses China Construction America’s appeal in US$1.6 billion Baha Mar fraud case

Wed 9 Apr 2025 at 05:59
RWLV names former MGM executive Greg Shulman as EVP of International Marketing

RWLV names former MGM executive Greg Shulman as EVP of International Marketing

Wed 9 Apr 2025 at 05:35
AGEM Index falls by 7.4% in December on Aristocrat, Light & Wonder stock price declines

AGEM Index down 9.3% in March as all 12 member firms suffer stock price declines

Fri 4 Apr 2025 at 02:46
After Donald Trump’s tariff barrage, US considering whether to eliminate tariff exemption for small parcels from Macau

After Donald Trump’s tariff barrage, US considering whether to eliminate tariff exemption for small parcels from Macau

Thu 3 Apr 2025 at 13:02
Load More
Tags: Aria Resort and CasinocybersecurityhackersMGM ResortsNorth America
Share13Share2
David Green

David Green

The founder of Newpage Consulting, David Green has advised on casino regulation in a number of geographies including New Zealand, Singapore, Macau, Cambodia and Japan. He served as Presiding Member of the Independent Gambling Authority in South Australia prior to relocating to Macau in 2001.

Current Issue

Editorial – The real reason Philippines casino revenues are down

Editorial – The real reason Philippines casino revenues are down

by Ben Blaschke
Sun 30 Mar 2025 at 23:04

After enjoying a post-COVID surge in gaming revenues at its licensed casinos, the Philippines has hit a rocky patch. In...

Inside Thai IRs

Inside Thai IRs

by Andrew W Scott and Ben Blaschke
Sun 30 Mar 2025 at 22:59

No time to read this whole article? Here are the bullet points! With passage of Thailand’s Entertainment Complex Bill through...

Resorts World Las Vegas – Lighting up the north

Resorts World Las Vegas – Lighting up the north

by Andrew W Scott and Ben Blaschke
Sun 30 Mar 2025 at 22:52

Inside Asian Gaming recently visited Genting’s American icon Resorts World Las Vegas to take a closer look at a property...

A baccarat perspective

A baccarat perspective

by Ryan Hong-Wai Ho
Sun 30 Mar 2025 at 22:37

In the first of a two-part series, Ryan Ho explores how gaming innovations and market changes have shaped the prominence...

Evolution Asia
Aristocrat
GLI
Mindslot
Solaire
Hann
Tecnet
Nustar
Jumbo

Related Posts

Bally’s Chairman Soo Kim talks after deal sealed to acquire Australia’s Star Entertainment

Bally’s Chairman Soo Kim talks after deal sealed to acquire Australia’s Star Entertainment

by Newsdesk
Wed 9 Apr 2025 at 06:16

Star Entertainment Group confirmed Monday it had entered into a binding term sheet with US casino operator Bally’s Corp to take control of the company as part of a US$300 million (US$180 million) deal. The term sheet, comprising a multi-tranche...

China-owned contractor of Chow Tai Fook’s Baha Mar ordered to pay US$1.6 billion to original owner for “many acts of fraud”

New York appellate court dismisses China Construction America’s appeal in US$1.6 billion Baha Mar fraud case

by Ben Blaschke
Wed 9 Apr 2025 at 05:59

A New York court has dismissed an appeal by China Construction America, Inc (CCA) against a Supreme Court ruling in October requiring it to pay US$1.6 billion to the original owner of Bahamas casino resort Baha Mar for committing “many acts...

Trade union warns massively increased casino pokies tax in NSW will cost jobs

Pub baron Bruce Mathieson agrees additional AU$100 million Star investment, reduces Bally’s contribution to AU$200 million

by Ben Blaschke
Wed 9 Apr 2025 at 05:40

Star Entertainment Group’s largest individual shareholder Investment Holdings Pty Ltd has entered into a binding term sheet with US casino operator Bally’s Corp that will see it subscribe for AU$100 million (US$60 million) in convertible bonds, reducing in the process...

RWLV names former MGM executive Greg Shulman as EVP of International Marketing

RWLV names former MGM executive Greg Shulman as EVP of International Marketing

by Newsdesk
Wed 9 Apr 2025 at 05:35

Genting Group’s US flagship Resorts World Las Vegas (RWLV) has announced the appointment of casino industry veteran Greg Shulman as Executive Vice President of International Marketing. Continuing the property’s recent management overhaul, RWLV said Shulman will lead its international casino...



IAG

© 2005-2024
Inside Asian Gaming.
All rights reserved.

  • SUBSCRIBE FREE
  • NEWSFEED
  • MAG ARTICLES
  • VIDEO
  • OPINION
  • TAGS
  • REGIONAL
  • EVENTS
  • CONSULTING
  • CONTRIBUTORS
  • MAGAZINES
  • ABOUT
  • CONTACT
  • ADVERTISE

No Result
View All Result
  • Subscribe
  • Newsfeed
  • Mag Articles
  • Video
  • Opinion
  • Tags
  • Regional
  • Events
  • Contributors
  • Magazines
  • Advertise
  • Contact
  • About
  • Home for G2E Asia

© 2005-2024
Inside Asian Gaming.
All rights reserved.

  • English