As Walmart’s newly redesigned shopping carts continue to roll out nationwide, some shoppers are complaining about arm and shoulder pain, saying the handlebar is too high for shorter customers. Other, presumably taller, shoppers are hailing the carts as a “game changer.”
In today’s email:
Casino cyberattacks: How MGM and Caesars were breached.
Subtraction by ad: It’s gonna be a long election season in the US.
Digits: Antarctica’s relatable crisis, an EV charge that lasted 99 hours, and more newsy numbers.
Around the web: A presidential UFO sighting, mummy smells, and a familiar alarm as a ballad.
👇 Listen: It’s time for companies to get wise to the devastating potential of cyberattacks.
The big idea
Scattered Spider, Alphv, and the MGM hack, explained
MGM’s high-profile hack sheds light on how devastating cyberattacks can be — but who’s responsible?
2023-09-18T00:00:00Z
Juliet Bennett Ryla
For the past several days, casino giant MGM has been gripped by a cyberattack.
Last Monday, MGM reported that a cybersecurity issue had impacted several systems, which it promptly shut down, perVox.
The hack wreaked havoc on its 12 Vegas properties’ digital room keys, slot machines, TVs, ATMs, and more, plus MGM’s websites.
How did it happen?
Techniques included “vishing” (“voice phishing”) and “social engineering,” or manipulating a person into revealing sensitive information.
In this case, hackers allegedly used publicly available LinkedIn info to impersonate an employee and tricked someone at MGM’s IT help desk into revealing access credentials.
Who did this?
That’s complicated, as two separate — but connected — groups have claimed responsibility.
Scattered Spider is believed to be a group of European and US hackers in their teens and 20s who specialize in social engineering.
Someone claiming to represent Scattered Spider told the Financial Times they wanted to rig the slot machines — a la Ocean’s Thirteen, which the rep said they’d never watched. When that failed, they decided to hold stolen data for ransom instead.
Scattered Spider also allegedly hacked Caesars Entertainment, which paid $15m in ransom.
Alphv/Black Cat runs a ransomware-as-a-service business, selling malware to other hackers. It was responsible for ~12% of cyberattacks in the first four months of 2022 and recently posted 2.5TB of data it stole from semiconductor maker Seiko.
Via a statement, it claimed to be the real culprit of the MGM hack (but not Caesars) and denied the slot machine plot.
While Spider is affiliated with Alphv and has used its malware in the past, it remains unclear how the two are connected — if at all — here.
Why?
Alphv seemed to enjoy excoriating MGM, accusing it of insider trading, shoddy privacy practices, and “greed, incompetence, and corruption.”
But mostly, money — MGM’s market cap is $14.4B. Ransomware hacks frequently target large organizations with money and sensitive info: hospitals, school systems, cities, etc.
Experts toldWired they hope high-profile hacks like MGM’s will bring more awareness to the devastating potential of cyberattacks — and perhaps new policies and strategies to combat them.
TRENDING
Empire state of mind: How often do men think about the Roman Empire? According to the latest social media trend, “a lot.” Women are taking to TikTok to ask the men in their lives this question, and it turns out some are daydreaming about ancient Rome as much as 3x a day.
SNIPPETS
United Auto Workerslaunched a targeted strike plan that will affect General Motors, Ford, and Stellantis. The strike began with 145k workers walking out of three auto plants in hopes of raising workers’ pay.
Meanwhile… America saw an estimated 4.1m missed days of work in August due to strikes, according to the Labor Department — the biggest monthly total since 2000.
TikTok is requiring many of its ~7k US employees to work in the office 3x a week beginning in October. Ahead of the transition, the company introduced an app that tracks employee badge swipes and absences.
Also worth keeping track of… European regulators fined TikTok $368m for failing to protect children’s accounts. Citations include setting kids’ profiles public by default and a lack of a verification process for its parental control security feature.
Lost and frowned: A new study suggests retailers lose $100B a year to consumer fraud techniques like return fraud, bots, and coupon stacking. One company polled claimed it lost $14m+ after 4k users created 137k fake accounts to take advantage of a discount code.
In related news… California is responding to a string of smash-and-grab retail robberies with $267m in spending to increase police presence and upgrade surveillance equipment statewide.
Planet Fitnessousted longtime CEO Chris Rondeau, who has held the position for over a decade. Shares plummeted 16% following the announcement, closing at ~$50 a share, the lowest level since 2020.
Princess Diana’s famed “Black Sheep” sweater sold at auction for $1.14m to someone who’s apparently unaware that the projected price was $80k — and that sweaters are only $19 at Old Navy right now.
Chart
Olivia Heller
The local TV business approves this message
Americans will be attacked by attack ads at a record clip over the next 14 months.
2023-09-18T00:00:00Z
Ben Berkley
If you find a good rock to hide under until Nov. 6, 2024, please let us know?
Another Election Day is fast approaching for Americans — just 413 days away, somehow — but political ad projections suggest it’ll feel like 413 years.
Campaign advertising spend is expected to hit a record $10.2B for the 2024 cycle, per ad-tracking firm AdImpact.
Our patience will lose, but who wins?
Incredibly, for an industry that’s been losing steam (and viewers) fast, local television will be a big beneficiary, projected to land half of the collective $10.2B ad spend, perBloomberg.
Which is… bizarre.
This summer, streaming services saw record viewership, outdrawing both broadcast TV and, for the first time, cable. Yet:
Local TV is expected to haul in $5.1B of the political ad spend, with cable TV landing $1.9B in prizes.
Streaming, meanwhile, is projected to see only $1.3B, with digital ads trailing behind at $1.2B.
At least radio’s place in all of this makes sense, accounting for only $400m.
What gives? Democratic operative Marc Levitt wrote in 2018 about the “warped” incentives of campaigns, which are “conditioned to prioritize… pricey TV ads.” He noted that older candidates and consultants, and their “TV era” orthodoxies, remained in charge.
That’s apparently still the case today; if anything shows off the slow-to-change ways of the political engine, it’s a traditional TV-led campaign spend.
But hey, at least…
… now you know to avoid your local stations for the next 14 months?
And if you’re already sick of it all, hang in there — to date, we’ve put $652m of campaign ads behind us, so there’s only another ~$9.55B worth of ads left to endure.
Free Resource
How to run team meetings like a boss
In spite of the movement to minimize meetings, we feel that weekly heat checks keep us aligned and flying in a unified direction.
But keep them brief — some notes are best said on Slack.
Managers can use this free guide on organizing meetings that respect everybody’s time. It runs through practical ways to handle invites, meetings, and follow-up comms.
Pretend like you had an epiphany. Pull up with a brand-new protocol.
Antarctica has a housing shortage too, unreal EV records, and more newsy numbers
Plus: A record “Super Mario Bros” speed run, and an increase in $100k+ American households.
2023-09-18T00:00:00Z
Ben Berkley
$74.8k: The median US household income in 2022, down 0.8% YoY, per the Census Bureau’s annual survey. Fortunately, though the median household income fell a tad, no state saw an increase in its poverty rate. Also notable: a 3% uptick in American households making $100k+, now up to 37% of homes.
4:54.631: The new record for speed-running “Super Mario Bros,” set by gamer Niftski. Per Ars Technica, this impressive feat requires a “pixel-perfect execution” of a particular level’s challenges and is just 0.35 seconds away from a machine speed run. For comparison, the average time to beat the game’s main story is two hours.
51%: Proportion of planned scientific missions canceled or curtailed at the United States Antarctic Program this summer. A leading reason for the reduction is a familiar story on the other six continents: a housing shortage. The National Science Foundation’s McMurdo Station is meant to host up to 1.2k scientists and support staff, but it’s a few hundred beds short. Covid and inflation have hampered a $500m renovation project, including a much-needed 285-bed dormitory.
1.6k miles: New record distance covered on a single charge by an EV prototype. Students from the Technical University of Munich who built the long-range EV drove it around an empty airplane hangar — for 99+ straight hours —until its battery died. Amateur Alps-adjacent scientists are on a roll this month: Students at the Academic Motorsports Club Zurich built another record-setting EV, this one recognized as the fastest accelerating electric car, going from zero to 62 mph in less than a full second.
AROUND THE WEB
👽 On this day: In 1973, former President Jimmy Carter reported a UFO sighting in Georgia. During his 1976 presidential campaign, he vowed to encourage the government to release all info on UFOs to the public, but later backtracked, citing national security.
🎹 That’s cool: The iPhone alarm, but make it a ballad.
Look at that! You’re on your way to the top of the food chain.
You seem like the kind of person who knows how to work a network. And now you’ve landed an opportunity to snag some business class aromatherapy.
Get {{5-contact.referral_count}} more referrals and you’ve got yourself a Hustle candle. Let us help you set the mood and bring some positive vibes to your workspace.
You’re just {{5-contact.referral_count}} referrals away. The candle awaits.
Look at that! You’re on your way to the top of the food chain.
You seem like the kind of person who knows how to work a network. And now you’ve landed an opportunity to snag the desk plant you never knew you needed.
Get {{15-contact.referral_count}} more referrals and you’ve got yourself a Hustle branded clover grow kit. If you want something to grow, you must water. Practice your nurturing abilities with this custom Hustle clover grow kit and grow your referrals at the same time.
You’re just {{15-contact.referral_count}} referrals away. Desk plant nirvana awaits.
Look at that! You’re on your way to the top of the food chain.
You seem like the kind of person who knows how to work a network. And now you’ve landed an opportunity to snag the desk organizer of all desk organizers.
Get {{25 – contact.referral_count}} more referrals and you’ve got yourself a Hustle-branded organizer, to hold your gadgets and give your desk space a breath of fresh air.
You’re just {{25 – contact.referral_count}} referrals away. The desk organizer awaits.
Look at that! You’re on your way to the top of the food chain.
You seem like the kind of person who knows how to work a network. And now you’ve landed an opportunity to organize all those stray cords floating around your desk.
Get {{50 – contact.referral_count}} more referrals and The Hustle tech organizer is yours. It’s clean, compact, and all you need to make sure your technology life support is closeby.
You’re just {{50 – contact.referral_count}} referrals away. The tech organizer awaits.
Look at that! You’re on your way to the top of the food chain.
You seem like the kind of person who knows how to work a network. And now you’ve landed an opportunity to snag the prestigious Hustle backpack.
Get {{100 – contact.referral_count}} more referrals and it’s yours. Carry your laptop, gym clothes, Coca Cola’s secret recipe, or whatever you feel like. Walk around with the crew on your back!
You’re just {{100 – contact.referral_count}} referrals away. A new bag awaits.
Look at that! You’re on your way to the top of the food chain.
You seem like the kind of person who knows how to work a network. And now you’ve landed an opportunity to snag some new tech.
Get {{250 – contact.referral_count}} more referrals and you’ve got yourself a Zoom Glow-up kit. This kit will include a Blue Yeti mic, Logitech camera, and a Lume Cube light. This is the perfect set-up to make every video recording and Zoom meeting feel like an Oscar-quality production. Keep climbing.
You’re just {{250 – contact.referral_count}} referrals away. The Zoom upgrade awaits.
Well, well. Look who climbed the ladder. We’re so proud.
You seem like the kind of person who knows how to work a network. And now you’ve got an opportunity to bag The Hustle’s grand prize.
Just {{500 – contact.referral_count}} more referrals and you’ll get yourself a ticket to Inbound 2023, the most bodacious business conference in the industry. You could rub shoulders with moguls, or catch a keynote next to your favorite YouTuber. Get your hustle on for a shot at maximizing your network.
You’re just {{500 – contact.referral_count}} referrals away. The final boss awaits.
Today’s email was brought to you by Juliet Bennett Rylah and Sara Friedman.
Editing by: Ben “Depressedly surfing on South Pole Zillow” Berkley.Was this email forwarded to you? Sign up here.
383.2B+: Possible latte variations Starbucks can make. Drink customizations add $1B+ in revenue annually — but workers loathe them and customers hate the...
We use cookies to make the Hustle website a better place. Cookies help to provide a more personalized experience and relevant advertising for you, and web analytics for us. To learn more about the different cookies we're using, check out our Cookie Settings. For further information, check out our Cookie Policy & our Privacy Policy.
This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Cookie
Duration
Description
__cf_bm
30 minutes
This cookie, set by Cloudflare, is used to support Cloudflare Bot Management.
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Cookie
Duration
Description
__hssc
30 minutes
This cookie keeps track of sessions.
This is used to determine if HubSpot should increment the session number and timestamps in the __hstc cookie.
It contains the domain, viewCount (increments each pageView in a session), and session start timestamp.
__hssrc
session
Whenever HubSpot changes the session cookie, this cookie is also set to determine if the visitor has restarted their browser.
If this cookie does not exist when HubSpot manages cookies, it is considered a new session.
It contains the value "1" when present.
__hstc
6 months
The main cookie for tracking visitors.
It contains the domain, utk, initial timestamp (first visit), last timestamp (last visit), current timestamp (this visit), and session number (increments for each subsequent session).
_ga
6 months
The _ga cookie, installed by Google Analytics, calculates visitor, session and campaign data and also keeps track of site usage for the site's analytics report. The cookie stores information anonymously and assigns a randomly generated number to recognize unique visitors.
_gat_gtag_UA_58267113_7
1 minute
This cookie is set by Google and is used to distinguish users.
_gat_UA-58267113-7
1 minute
This is a pattern type cookie set by Google Analytics, where the pattern element on the name contains the unique identity number of the account or website it relates to. It appears to be a variation of the _gat cookie which is used to limit the amount of data recorded by Google on high traffic volume websites.
_gcl_au
3 months
Provided by Google Tag Manager to experiment advertisement efficiency of websites using their services.
_gid
1 day
Installed by Google Analytics, _gid cookie stores information on how visitors use a website, while also creating an analytics report of the website's performance. Some of the data that are collected include the number of visitors, their source, and the pages they visit anonymously.
_hjAbsoluteSessionInProgress
30 minutes
This cookie is set by Hotjar. Used to detect the first pageview session of a user.
_hjFirstSeen
session
This cookie is set by Hotjar. Identifies a new user’s first session.
Used by Recording filters to identify new user sessions.
_hjIncludedInPageviewSample
30 minutes
This cookie is set by Hotjar. Set to determine if a user is included in the data sampling defined by the website limit.
_hjIncludedInSessionSample
30 minutes
This cookie is set by Hotjar. Set to determine if a user is included in the data sampling defined by your site's daily session limit.
_hjSession_1955701
30 minutes
This cookie is set by Hotjar. Holds current session data.
Ensures subsequent requests in the session window are attributed to the same session.
_hjSessionUser_1955701
1 year
This cookie is set by Hotjar.
Set when a user first lands on a page.
Persists the Hotjar User ID which is unique to that site.
Ensures data from subsequent visits to the same site are attributed to the same user ID.
_omappvp
6 months
The _omappvp cookie is set to distinguish new and returning users and is used in conjunction with _omappvs cookie.
_omappvs
20 minutes
The _omappvs cookie, used in conjunction with the _omappvp cookies, is used to determine if the visitor has visited the website before, or if it is a new visitor.
_omra
6 months
This cookie is set by OptinMonster. Used to store interaction and conversion data for campaigns in conjunction with Revenue Attribution.
hubspotutk
6 months
This cookie keeps track of a visitor's identity. It is passed to HubSpot on form submission and used when deduplicating contacts.
It contains an opaque GUID to represent the current visitor.
om-wip10afyetrnlu70kibe
1 month
Used to determine if a visitor has been shown a campaign by the slug
sailthru_content
1 year
This cookie is set by Sailthru. Tracks recent pageviews for all visitors, and can be used to populate a new user profile.
sailthru_pageviews
30 minutes
This cookie is set by Sailthru to tracks the number of page views for each user.
sailthru_visitor
1 year
This cookie is set by Sailthru. The cookie contains an id that is used to identify a user’s pageviews within a session.
test_cookie
15 minutes
The test_cookie is set by doubleclick.net and is used to determine if the user's browser supports cookies.
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Cookie
Duration
Description
_clck
1 year
This cookie is set by Microsoft Clarity. Persists the Clarity User ID and preferences, unique to that site, on the browser. This ensures that behavior in subsequent visits to the same site will be attributed to the same user ID.
_clsk
1 year
This cookie is set by Microsoft Clarity. Connects multiple page views by a user into a single Clarity session recording.
_cq_check
Session
This cookie is set by CHEQ AI Technologies. Used to monitor the technical information and use of devices that connect to our website to protect it from malicious traffic.
_cq_duid
3 month
This cookie is set by CHEQ AI Technologies. Used to monitor the technical information and use of devices that connect to our website to protect it from malicious traffic.
_cq_suid
Session
This cookie is set by CHEQ AI Technologies. Used to monitor the technical information and use of devices that connect to our website to protect it from malicious traffic.
_fbp
3 months
This cookie is set by Facebook to display advertisements when either on Facebook or on a digital platform powered by Facebook advertising, after visiting the website.
_lc2_fpi
2 years
This cookie is set by LiveIntent. A random, unique, device identifier, stored as a 1st party cookie, to enable targeted advertising
_li_dcdm_c
session
This cookie is set by LiveIntent. The domain name where the _lc2_fpi cookie was stored
_tt_enable_cookie
13 months
To measure and improve the performance of your advertising campaigns and to personalize the user's experience (including ads) on TikTok.
_tt_sessionId
13 months
To measure and improve the performance of your advertising campaigns and to personalize the user's experience (including ads) on TikTok.
_ttp
13 months
To measure and improve the performance of your advertising campaigns and to personalize the user's experience (including ads) on TikTok.
_twclid
30 days
This cookie is set by Twitter. It is used for tracking and personalization purposes, such as remembering a user's preferences and activity on the site.
_uetsid
1 day
This cookie is set by Microsoft Advertising. It contains the session ID for a unique session on the site.
_uetvid
13 months
This cookie is set by Microsoft Advertising. UET assigns this unique, anonymized visitor ID, representing a unique visitor. UET stores this data in a first-party cookie.
AnalyticsSyncHistory
1 month
Linkedin sets this cookie. Used to store information about the time a sync took place with the lms_analytics cookie
ANONCHK
10 minutes
This cookie is set by Microsoft Clarity. Indicates whether MUID is transferred to ANID, a cookie used for advertising. Clarity doesn't use ANID and so this is always set to 0.
auth_token
5 years
This cookie is set by Twitter. It is used for authentication purposes, to keep the user logged in to their Twitter account.
bcookie
1 year
This cookie is set by LinkedIn. Browser Identifier cookie to uniquely identify devices accessing LinkedIn to detect abuse on the platform.
bscookie
1 year
This cookie is set by Linkedin. Used for remembering that a logged in user is verified by two factor authentication.
cg_uuid
1 year
Sets a unique ID for the visitor that allows third-party advertisers to target the visitor with relevant advertisements. This pairing service is provided by third-party advertisement hubs, which facilitates real-time bidding for advertisers.
CLID
1 year
Identifies the first-time Clarity saw this user on any site using Clarity.
fr
3 months
Facebook sets this cookie to show relevant advertisements to users by tracking user behaviour across the web, on sites that have Facebook pixel or Facebook social plugin.
guest_id
1 year
This cookie is set by Twitter to identify and track the website visitor.
guest_id_ads
1 year
This cookie is set due to Twitter integration and sharing capabilities for the social media.
guest_id_marketing
1 year
Used to detect whether a user is logged into Twitter.
lang
Session
This cookie is set by Linkedin. Used to remember a user's language setting to ensure LinkedIn.com displays in the language selected by the user in their settings.
li_gc
6 months
This cookie is set by Linkedin. Used to store consent of guests regarding the use of cookies for non-essential purposes.
lidc
24 hours
Linkedin sets this cookie. Used To facilitate data center selection.
lidid
2 years
This cookie is set by LiveIntent. A random, unique, device identifier, stored as a 3rd party cookie, used to enable targeted advertising
muc_ads
2 years
Collects data on user behaviour and interaction in order to optimize the website and make advertisement on the website more relevant
MUID
9 months
This cookie is set by Microsoft Advertising. Identifies unique web browsers visiting Microsoft sites. These cookies are used for advertising, site analytics, and other operational purposes.
personalization_id
2 years
This cookie is set due to Twitter integration and sharing capabilities for the social media.
SM
session
This cookie is set by Microsoft Clarity. Used in synchronizing the MUID across Microsoft domains.
SRM_B
1 year 24 days
This cookie is set by Microsoft Clarity. Identifies unique web browsers visiting Microsoft sites.
UserMatchHistory
1 month
Linkedin sets this cookie. Used for id sync process. It stores the last sync time to avoid continually repeating the syncing process.
X-AB
1 day
This cookie is set by Snapchat. This is a tool used to combine or change content on the website. This allows the website to find the best variation/edition of the site.