Hackers who breached casino giants MGM, Caesars also hit 3 other firms, Okta says

SAN FRANCISCO听–听贬补肠办别谤蝉听飞丑辞听产谤别补肠丑别诲听肠补蝉颈苍辞听驳颈补苍迟蝉听惭骋惭听Resorts International聽and听颁补别蝉补谤蝉听Entertainment聽in recent weeks听补濒蝉辞听broke into the systems of three听辞迟丑别谤听companies in the manufacturing, retail, and technology space, a security executive familiar with the matter said.
David Bradbury, chief security officer of the identity management company听翱办迟补, said five of the company’s clients, including聽惭骋惭听and听颁补别蝉补谤蝉, had fallen victim to hacking groups known as ALPHV and Scattered Spider since August.
In an interview with Reuters, Bradbury didn’t name the听辞迟丑别谤听companies, but said听翱办迟补聽was cooperating with official investigations into the breaches.
The hacks have cast fresh spotlight on ransomware attacks – cyber intrusions that affect hundreds of companies every year, from healthcare providers to telecom听蹿颈谤尘蝉.聽惭骋惭听and听颁补别蝉补谤蝉听lost market value last week as stock prices fell, and聽惭骋惭听is yet to recover from various operations disrupted at the hotels and gaming venues it owns from Las Vegas to Macau.
San Francisco-based听翱办迟补, which听蝉补测蝉听it has more than 17,000 customers around the world, provides identity services such as multi-factor authentication used to help users securely access online applications and websites. Multiple breaches it identified at its customers last month prompted the company to issue an聽聽then, Bradbury said.
“We saw this happened in such a small period of time and we thought we should be coming forward to the industry at large and explaining what’s happening here,” he said.
At the time,听翱办迟补聽said its US customers were reporting a consistent pattern of attacks where听丑补肠办别谤蝉听impersonated a victim firm’s employees and convinced their information technology helpdesk into providing them duplicate access.
“We’ve seen consistently over the past six to 12 months, a ramp up in these types of attacks,” Bradbury said.
惭骋惭听has not commented on the statement or the hack, beyond saying last week that it was dealing with a “cybersecurity issue.”听颁补别蝉补谤蝉听别补谤濒颈别谤听聽it was investigating the breach.
The financially-motivated hacking group ALPHV claimed the聽惭骋惭听hack in a post on its website Friday, and warned聽惭骋惭听of further attacks if it didn’t strike a deal. It’s unclear how much ransom ALPHV has demanded.
Bradbury said the group had聽产谤别补肠丑别诲听into聽惭骋惭听and obtained access to its听翱办迟补聽client, which allowed it further access to more credentials in the identity management firm’s system.
Scattered Spider appears to have worked with ALPHV on the latest hacks, Bradbury said, citing research by security analysts聽飞丑辞听have tracked both groups. “Think of them more as business associates or affiliates,” he said.
Google’s Mandiant Intelligence last week called Scattered Spider,听补濒蝉辞听known as UNC3944, as one of the most disruptive hacking outfits in the United States. Bradbury said Mandiant’s description of the group’s tactics aligned with what听翱办迟补聽had observed in the recent hacks. – Reuters


