MGM and Caesars Casino Hackers Jailed in Record UK Cybercrime Case

Two members of Scattered Spider, the cyber-crime group behind the attacks on Las Vegas casino giants MGM Resorts and Caesars Entertainment, have been jailed in what the National Crime Agency called the UK’s biggest cyber crime prosecution.
The two men were each sentenced to five years and six months at Woolwich Crown Court.
The pair were sentenced over a separate attack on Transport for London, but both belong to the loose hacking collective whose 2023 casino breaches became a wake-up call for the gambling industry.
For players, the case is a reminder of how the biggest names in online casinos and land-based gaming can be brought down not by clever code, but by a convincing phone call.
Who Are Scattered Spider?
Scattered Spider is a hacking group mostly made up of teens and young adults. A collective that grew out of online communities and specialises in social engineering: manipulating people rather than breaking encryption.
Their fluency in English sets them apart from many overseas cybercriminal networks and makes their phone-based scams far more convincing.
The group targeted telecom, tech, retail, and casino sectors, but its reputation was truly forged during the near-simultaneous strikes on MGM and Caesars.
How The Casino Hacks Unfolded
The attack on MGM Resorts started with research, not malware. Having identified an employee to impersonate, the attackers phoned MGM’s IT help desk, posed as that member of staff and talked their way into working login credentials, according to a detailed breakdown by security firm Netwrix.
They then somehow gained administrator access to MGM’s Okta and Microsoft Azure identity systems, moved laterally through the network and brought in the ALPHV, or BlackCat, ransomware crew.
Around 100 servers were encrypted, knocking slot machines offline, disabling digital room keys and taking down booking and reservation systems for days.
Why These Two Were Jailed
Both were sentenced not for the casino attacks but for a September 2024 strike on Transport for London that the NCA said cost around £29 million in losses and recovery.
The lead hacker has also been linked to at least 120 network intrusions affecting 47 organisations, with victims paying at least $115 million in ransoms, according to the Department of Justice.
Paul Foster, head of the NCA’s National Cyber Crime Unit, said Scattered Spider "has been the most significant cybercrime threat to the UK in recent years".
The Tactics To Watch Out For
What makes Scattered Spider dangerous to ordinary players is that its methods do not require you to be hacked directly.
The group’s trademark is social engineering: impersonating staff or customers to trick a human into handing over access.
The same playbook is turned on consumers after a breach. Once a casino’s customer database is stolen, criminals use those real names, emails and phone numbers to send convincing phishing emails, fake text messages and vishing (voice phishing) calls that appear to come from the operator.
A message that knows your name, your account and your recent activity is far harder to dismiss than a random scam.
How Players Can Stay Safe
You cannot stop a casino being breached, but you can limit what it means for you. A few habits make a real difference:
- Turn on two-factor authentication on every gambling and email account, ideally with an authenticator app rather than SMS.
- Use a unique password for each casino, backed by a password manager, so a leak on one site cannot unlock the others.
- Never share a one-time code. No legitimate operator will ever phone or message asking you to read out a verification code or password.
- Treat unexpected contact with suspicion, even if it looks official. Go to the site or app directly instead of clicking links in emails or texts.
- Watch your accounts after any breach notice, and take up any free credit or identity monitoring you are offered.
What Casinos Are Doing To Fight Back
The 2023 attacks exposed the IT help desk as the industry’s soft underbelly, and operators have moved to close it.
MGM alone pledged up to $40 million in security upgrades, including stronger access controls and better authentication, after the breach.
The response has centred on tougher identity checks before help desks reset passwords or multi-factor authentication, a shift to phishing-resistant security keys, "zero trust" network design that limits how far an intruder can move, and far more staff training on the social-engineering tricks Scattered Spider relies on.
Regulators, including the Gambling Commission, expect licensed operators to protect customer data as a condition of their licence.



