---
title: "Ransomware, Zero Trust, and Microsegmentation: Lessons Learned from the MGM Ransomware Attack"
description: What can cybersecurity leaders learn from the recent ransomware attacks on MGM?  Identity-based Zero Trust access control and Microsegmentation with Invisinet can stop such attackers.
image: https://blog.invisinet.com/hubfs/Canva%20images/Canva%20Design%20DAFvqZANVSw.png
---

[![Invisinet](https://blog.invisinet.com/hs-fs/hubfs/raw_assets/public/invisinet-2024/images/invisinet-logo.png?width=350&height=2064&name=invisinet-logo.png "Invisinet")](https://www.invisinet.com/)

- Solutions 
    - [Platform Overview](http://www.invisinet.com/solution)
    - [IIoT Solutions](http://www.invisinet.com/solutions-for-iiot)
    - [Enterprise Solutions](http://www.invisinet.com/solutions-for-enterprise)
- Industries 
    - [Manufacturing](http://www.invisinet.com/industries/manufacturing)
    - [Energy](http://www.invisinet.com/industries/energy-oil-gas)
    - [Government](http://www.invisinet.com/industries/government-infrastructure)
    - [Healthcare](http://www.invisinet.com/industries/healthcare)
- Resources 
    - [Resources main](http://www.invisinet.com/resource)
    - [FAQs](http://www.invisinet.com/faqs)
    - [Blog](https://blog.invisinet.com/blogs)
- Company 
    - [About Us](http://www.invisinet.com/about-us)
    - [Leadership](http://www.invisinet.com/leadership)
    - [Contact Us](http://www.invisinet.com/contact-us)
    - [News Releases](http://www.invisinet.com/news-releases)
- [Partners](http://www.invisinet.com/partners)

[Get a Demo](https://blog.invisinet.com/get-a-demo)

Search

- There are no suggestions because the search field is empty.

Blog

# Ransomware, Zero Trust, and Microsegmentation: Lessons Learned from the MGM Ransomware Attack

![Lindsay Hiebert, Senior Product Manager](https://blog.invisinet.com/hubfs/Lindsay-Hiebert.jpeg)

Author : [Lindsay Hiebert, Senior Product Manager](https://blog.invisinet.com/blogs/author/lindsay-hiebert)

September 27, 2023

In September 2023, MGM Resorts International, one of the world's largest gaming and hospitality companies, was hit by a ransomware attack. The attack impacted all of MGM's properties in Las Vegas and some of its properties in other parts of the country.

The attack was carried out by a ransomware group known as ALPHV. ALPHV is a relatively new ransomware group, but it has quickly become one of the most active and dangerous ransomware groups in the world.

The MGM ransomware attack resulted in significant financial losses, operations disruption, and raised concerns about the security of the gaming and hospitality industry. The impact is estimated to be tens of millions of dollars, including closures of casinos and hotels, cancellation of events, loss of customer data, and damage to MGM's reputation. The attack also negatively impacted the Las Vegas economy, with businesses that rely on MGM's customers experiencing a decline in sales.

**Lessons Learned from the MGM Ransomware Attack**

The MGM ransomware attack provides a number of important lessons for cybersecurity leaders:

- **Zero trust is essential:** Zero trust is a security model that assumes that no user or device can be trusted by default. All users and devices must be verified before they are granted access to any resources.

A zero trust security model would have made it much more difficult for ALPHV to carry out its attack. With a zero trust model, ALPHV would have needed to compromise multiple systems and accounts in order to gain access to MGM's critical systems.

- **Microsegmentation is critical:** Microsegmentation is a security technique that divides a network into small segments. Each segment is isolated from the other segments, and only authorized users and devices can access each segment.

Microsegmentation would have helped to limit the damage caused by the MGM ransomware attack. If ALPHV had been able to encrypt data in one segment of the network, the other segments would have been unaffected.

- **Multi-factor authentication is a must:** Multi-factor authentication (MFA) adds an extra layer of security to user accounts. With MFA, users must enter a code from their phone in addition to their password when logging in.

MFA would have made it much more difficult for ALPHV to gain access to MGM's systems. Even if ALPHV had been able to steal passwords, they would not have been able to log in to MGM's systems without the MFA codes.

- **Security awareness training is essential:** Employees are often the weakest link in the security chain. Security awareness training can help employees to identify and avoid common phishing attacks and other social engineering attacks.

Security awareness training would have helped to reduce the risk of the MGM ransomware attack. If employees had been trained to identify and avoid social engineering attempts on phone, phishing emails, etc., ALPHV would have had a much harder time gaining access to MGM's systems.

 

**Invisinet** offers a simpler approach to prevent cyber-attacks. Our solution offers  foundation of Zero Trust with identity that can help stop network discovery and ransomware attacks from the outset. Please reach out to [schedule an expert demo](https://share.hsforms.com/1k5ad3uDKSFSWKR9uD9Fulgeimee) for your team.

 

Tags: [Blog](https://blog.invisinet.com/blogs/tag/blog)

## Related posts

<https://blog.invisinet.com/blogs/sec-compliance-otsecurity>

##### [The Best Preparation Is Proactive Prevention with Zero Trust](https://blog.invisinet.com/blogs/sec-compliance-otsecurity)

The Securities and Exchange Commission (SEC) recently enacted new cybersecurity rules that require...

September 18, 2023

<https://blog.invisinet.com/blogs/dynamic-micro-segmentation>

##### [Is Your Network Security Prepared for Advanced Persistent Threats?](https://blog.invisinet.com/blogs/dynamic-micro-segmentation)

In today's digital age, protecting our data is of utmost importance. However, as technology...

August 28, 2023

<https://blog.invisinet.com/blogs/identity-based-solutions-for-network-security>

##### [Identity-Based Solutions for Network Security](https://blog.invisinet.com/blogs/identity-based-solutions-for-network-security)

A significant weakness in any IP-based enterprise is that source addresses which can be...

May 2, 2023

## Subscribe for monthly cyber physical security insights.

### Subscribe for our monthly cyber security insights

- [Home](http://www.invisinet.com)
- Solutions 
    - [Platform Overview](http://www.invisinet.com/solution)
    - [IIoT Solutions](http://www.invisinet.com/solutions-for-iiot)
    - [Enterprise Solutions](http://www.invisinet.com/solutions-for-enterprise)
- Industries 
    - [Manufacturing](http://www.invisinet.com/industries/manufacturing)
    - [Energy](http://www.invisinet.com/industries/energy-oil-gas)
    - [Government](http://www.invisinet.com/industries/government-infrastructure)
    - [Healthcare](http://www.invisinet.com/industries/healthcare)

- Resources 
    - [Resources main](http://www.invisinet.com/resource)
    - [FAQs](http://www.invisinet.com/faqs)
    - [Blog](https://blog.invisinet.com/blogs)
- Company 
    - [About](http://www.invisinet.com/about-us)
    - [Leadership](http://www.invisinet.com/leadership)
    - [Contact Us](http://www.invisinet.com/contact-us)
    - [News Releases](http://www.invisinet.com/news-releases)
- [Partners](http://www.invisinet.com/partners)

[![Invisinet](https://blog.invisinet.com/hs-fs/hubfs/raw_assets/public/invisinet-2024/images/invisinet-footer-logo.png?width=350&height=2064&name=invisinet-footer-logo.png "Invisinet")](https://blog.invisinet.com/)

4422 Cypress Creek Parkway,  
 Suite 250 Houston,  
 TX 77068

- <https://www.linkedin.com/company/invisinettechnologies/>
- <https://www.youtube.com/@InvisinetTechnologies>

[Privacy Policy](https://www.invisinet.com/privacy-policy)

[Cookie Policy](https://www.invisinet.com/cookie-policy)

[Terms and Conditions](https://www.invisinet.com/terms-and-conditions)

© 2026 Invisinet | All Right Reserved.

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Lindsay Hiebert, Senior Product Manager",
    "url" : "https://blog.invisinet.com/blogs/author/lindsay-hiebert"
  },
  "dateModified" : "2023-09-27T23:06:30.674Z",
  "datePublished" : "2023-09-27T18:20:02.000Z",
  "headline" : "Ransomware, Zero Trust, and Microsegmentation: Lessons Learned from the MGM Ransomware Attack",
  "image" : [ "https://blog.invisinet.com/hubfs/Canva%20images/Canva%20Design%20DAFvqZANVSw.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.invisinet.com/blogs/ransomware-zero-trust-and-microsegmentation-lessons-learned-from-the-mgm-ransomware-attack",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.invisinet.com/hubfs/Artboard%204%20copy.jpg"
    },
    "name" : "Invisinet"
  }
}
```