CISA plans to release final CIRCIA regulations in September 2026. This regulation forces 300,000 public and private entities within 16 critical infrastructure sectors to report substantial cyber incidents. Organizations must report such incidents within 72 hours. They must also report any ransomware payments within 24 hours. This regulatory expansion forces organizations to improve visibility into complex IT and operational technology environments. Incident response workflows can no longer wait for full forensic confirmation or extended leadership deliberations.
The MGM settlement mechanics
A federal court gave preliminary approval to a $45 million settlement against MGM Resorts International. This settlement resolves a consolidated class-action lawsuit regarding two data breaches in 2019 and 2023. The 2023 ransomware attack impacted approximately 37 million customers. The 2019 incident involved the theft of personal information for 10.6 million users. The settlement uses a tiered system to distribute funds based on the specific type of information an individual had exposed. The deadline to submit a claim for these benefits passed on June 3, 2025.
| Information Type | Estimated Tiered Cash Payment |
|---|---|
| Social Security or Military ID | $75.00 |
| Passport or Driver’s License | $50.00 |
| Name, Address, or Date of Birth | $20.00 |
| Documented Financial Loss | Up to $15,000.00 |
The $45 million settlement covers victims through a tiered system that distributes funds based on the specific type of private information an individual had exposed during the 2019 and 2023 data incidents.
The five steps of the attack
The attackers followed a five-step process to breach the network. They started with reconnaissance on professional networks to find employee details. This research allowed them to pick targets to impersonate. They used vishing to call the IT help desk. They convinced agents to reset passwords and multi-factor authentication factors. This sequence collapsed the authentication model into a single conversation. The attackers then added new identity providers to the environment. They used these providers to generate forged Security Assertion Markup Language tokens. These tokens carried claims that multi-factor authentication was satisfied. This method allowed them to gain administrator access. Finally, the attackers deployed ransomware to encrypt VMware ESXi servers. They also exfiltrated data to sites like MEGA.NZ.
MGM operational and financial impact
The MGM ransomware attack caused ten days of disruption across the property portfolio. The company reported a $100 million negative impact to Adjusted Property EBITDAR. They also recorded under $10 million in one-time expenses in the third quarter of 2023. The disruption affected hotels such as the Bellagio, Aria, MGM Grand, and Mandalay Bay. Staff had to manage hotel operations manually for ten days. Guests reported that digital room keys stopped working. Online booking systems and mobile services also became inaccessible. Slot machines went offline and displayed error messages. Employees had to calculate slot machine wins and losses by hand. The company also faced $84 million in lost revenue.
The Scattered Spider profile
Scattered Spider is the group responsible for the MGM breach. They are an affiliate of the ALPHV/BlackCat ransomware-as-a-service operation. This group is a financially motivated collective of native English-speaking threat actors. They use techniques like SIM swapping, multi-factor authentication fatigue, and vishing. They target high-value identities to gain access to cloud environments like Microsoft Azure and Okta. The group is also known by aliases such as Octo Tempest and 0ktapus. They have targeted other large organizations including Caesars Entertainment, Visa, and Twilio.
Comparing ransomware losses
Ransomware costs vary across different incidents. MGM faced a $100 million loss while Caesars paid a $15 million ransom for a similar attack. Cencora paid roughly $75 million in Bitcoin to the Dark Angels group. The Change Healthcare incident resulted in damages exceeding $2.45 billion. The financial scale of ransomware varies between individual companies and entire sectors. The $45 million MGM settlement addresses consumer losses, while the Change Healthcare incident caused over $2.45 billion in total damage.
CISA warning program changes
CISA manages a program that warns organizations about imminent ransomware. David Stern led the Pre-Ransomware Notification Initiative before he resigned in December 2025. The program used tips from the intelligence community and cybersecurity firms. It sent over 1,200 warnings in 2023 and 2,100 in 2024. These notifications helped prevent attacks on water systems, energy utilities, and healthcare organizations. Stern estimated these notifications saved companies billions in potential damages. The program is now in a state of transition as the agency prepares other staffers to take over the work.
The visibility mandate
The September 2026 deadline forces a shift in how companies handle visibility. Incident response workflows cannot wait for forensic investigations. Organizations must have data inventories and tested escalation paths. You already know the basics of identity management, so look at how a single phone call bypassed MGM’s entire authentication model. MGM’s public disclosures center on technical controls, not the help-desk identity-verification step that Scattered Spider defeated. Will the CISA reporting mandates force companies to change their help desk protocols? Regulatory enforcement is now a matter of timing for critical infrastructure entities.
