Concerns Rise Over Potential Surge in Ransomware as Young Western Hackers Collaborate with Russians

Over the past year, various sectors—including hospitals, pharmacies, tech firms, and some of Las Vegas’ most iconic hotels and casinos—have been crippled by “ransomware” attacks. These cybercrimes involve hackers infiltrating corporate networks, encrypting essential data, and demanding a ransom for its release. As we reported in April, the frequency and severity of these attacks have been escalating each year. Now, cybersecurity experts warn that the situation is poised to worsen, particularly with the rise of a bold new group of young hackers from the U.S., U.K., and Canada known as Scattered Spider, who have reportedly joined forces with Russia’s infamous ransomware collective.

In September, MGM Resorts fell victim to one of the most damaging ransomware attacks in history, costing the company over $100 million. The attack disrupted operations at several of Las Vegas’ most prestigious hotels and casinos, including MGM Grand, Aria, Mandalay Bay, New York-New York, and the Bellagio.

Anthony Curtis, a well-known figure in Las Vegas, was on-site when the attack occurred. Renowned for his card-counting skills, Curtis now publishes the “Las Vegas Advisor,” a newsletter dedicated to all things Vegas.

Anthony Curtis: Remarkably, I was actually at an MGM property when the attack happened. We were having dinner when we started hearing rumors that something was wrong. When I went down to the casino, I saw that the slot machines were dark, and people were in a state of confusion. The shutdown was becoming apparent.
Across the Vegas strip, thousands of slot machines suddenly ceased to function.

Anthony Curtis: Suddenly, people were asking, “How do I get my money? What’s going on?” People were waiting, unable to get paid.

Bill Whitaker: Were they upset?

Anthony Curtis: They were getting angry, yes. And this was just the beginning.

The attack caused elevators to malfunction, parking gates to freeze, and digital door keys to stop working. As systems failed, reservations were locked up, and long lines formed at the front desks.

Anthony Curtis: Anything reliant on technology was down.

Bill Whitaker: It sounds chaotic.

Anthony Curtis: It was, and even the employees were at a loss. They could only ask for patience and understanding.

At a conference in October, MGM’s CEO, Bill Hornbuckle, described the attack as “corporate terrorism at its finest.” The company declined our request for an interview, but Hornbuckle admitted that the disruptions were devastating.

Bill Hornbuckle (at October conference): For four or five days, with 36,000 hotel rooms and regional properties, we were completely in the dark.

The hackers demanded $30 million to release MGM’s data. Although MGM refused to pay, the company still faced a loss of $100 million in revenue and additional millions to rebuild their servers.

The hackers gained access through a technique known as social engineering. They targeted an employee, gathering information from sources like the dark web and LinkedIn. Then, posing as the employee, a hacker called the MGM Tech Help Desk and convinced them to reset the password.

Once inside MGM’s systems, the hacker unleashed the malware. Curtis likened the cybercriminals’ actions to an Ocean’s Eleven heist.

Anthony Curtis: They’re doing it the modern way but with an old-school goal. They want the money.

Bill Whitaker: What do you think of that?

Anthony Curtis: I don’t want to praise them—they’re criminals. But these hackers outsmarted the casinos, which have systems, protections, experts, and security. These guys were better.

Shortly after, MGM’s biggest competitor, Caesars, revealed that it had also suffered a social engineering attack, likely by the same group. Unlike MGM, Caesars paid a $15 million ransom and avoided major disruptions.

Bryan Vorndran, head of the FBI’s Cyber Division, advised against paying ransoms but acknowledged that it’s a business decision during a crisis. He noted that ransomware attacks are becoming increasingly audacious.

Bryan Vorndran: The numbers show it’s a significant problem for the global and U.S. economies and national security. Estimates suggest global losses exceed $1 billion annually.

Bill Whitaker: Have there been any arrests related to the Las Vegas attacks?

Bryan Vorndran: We can’t discuss specific cases or companies.

However, Vorndran pointed to Scattered Spider as a prime suspect.

Bryan Vorndran: Scattered Spider is a criminal group that’s been on our radar due to the havoc they’re causing across the U.S.

Scattered Spider is a loose network of predominantly English-speaking hackers responsible for the casino attacks and many others. Their expertise lies in social engineering.

Allison Nixon, Chief Research Officer at Unit 221b, a cybersecurity firm specializing in English-speaking cybercriminals, explained that Scattered Spider is part of a larger subculture called “the Community” or “the Com.”

Allison Nixon: The Com is a new, disruptive subculture of English-speaking youth. What started as a few hundred members has exploded into thousands since 2018, driven by the influx of money.

Bill Whitaker: How are they connected?

Allison Nixon: They connect through the internet—social spaces, gaming servers. It’s like an online back alley where bad kids hang out.

Bill Whitaker: How old are they?

Allison Nixon: Mostly males under 25, some as young as 13 or 14.

Bill Whitaker: Involved in major crimes?

Allison Nixon: Yes.

Members communicate via messaging apps like Telegram, where they share a toxic mix of racism, sexism, and boasts about their criminal exploits.

Allison Nixon: These online spaces glorify crime, measuring self-worth by the amount of harm one can cause.

Scattered Spider’s sophistication attracted attention from other hackers, including Russia’s notorious BlackCat ransomware gang. Despite cultural and language barriers, the two groups have formed a powerful partnership. Scattered Spider provides access to Western companies’ networks, while BlackCat supplies its malware and expertise, resulting in devastating attacks like the one on MGM.

Jon DiMaggio, a former NSA analyst and now chief security strategist at cybersecurity firm Analyst1, described the evolution of ransomware as a service. Russian gangs like BlackCat offer their tools and expertise to affiliates like Scattered Spider, sharing the profits from successful attacks.

Jon DiMaggio: Russian ransomware groups operate like legitimate companies with online platforms, 24-hour support, and even HR departments.

DiMaggio noted that the Russian government provides a safe haven for these criminals, as long as they avoid targeting Russian interests.

Jon DiMaggio: It’s not considered a crime to attack American businesses.

Bill Whitaker: So they operate with impunity?

Jon DiMaggio: 100%. That’s why it’s such a popular crime.

Russian ransomware has become such a threat that the National Security Agency has stepped up its efforts. Before retiring, Rob Joyce, former NSA director of cybersecurity, explained that the 2021 Colonial Pipeline attack was a wake-up call.

Rob Joyce: We realized we needed to dedicate more resources to combat this foreign threat. The NSA has hackers, and sometimes it takes a hacker to defeat a hacker. That’s our value—we can identify the individuals behind these activities.

The NSA helped identify the Russian hacker responsible for the Colonial Pipeline attack. In January 2022, after months of negotiations, Russia arrested him and others. However, after the invasion of Ukraine, they were released and resumed their criminal activities.

Rob Joyce: Yes, they’re back in business.

Now, with the collaboration between Russian hackers and Scattered Spider, the FBI’s Vorndran warns of a new evolution in cybercrime.

Bryan Vorndran: Scattered Spider’s partnership with BlackCat is formidable. We’re up against a highly capable adversary, but we’re also very good at what we do.

In January, the FBI arrested 19-year-old Noah Urban from Florida for cryptocurrency theft. While he’s pleaded not guilty, investigators have linked him to Scattered Spider. Two more arrests followed, both connected to the casino hack, but many remain at large. Allison Nixon sees Las Vegas as a sign of what’s to come.

Allison Nixon: Cybercrime has reached an overwhelming level. Every year, it gets worse. As defenders, it’s like we’re winning battles but losing the war.

More Articles & Posts