In September 2023 the cybercrime group Scattered Spider compromised MGM Resorts International through a 10 minute phone call to the IT help desk, gained access to Okta and Azure Active Directory, deployed BlackCat ransomware across MGM's systems, and caused an estimated $100 million in losses. Casino floors went dark. Hotel room keys stopped working. ATMs went offline. MGM refused to pay the ransom. Caesars Entertainment was hit by the same group days earlier and quietly paid $15 million.
Initial Access
Vishing Help Desk Attack
confirmed
Scattered Spider operatives called MGM's IT help desk impersonating an employee. Using information gathered from LinkedIn about a real MGM employee they convinced the help desk to reset credentials and grant access. The entire social engineering attack took approximately 10 minutes on the phone.
Defender cut points
Implement strict identity verification protocols for all help desk credential reset requestsRequire callback verification to known employee numbers before any account changesTrain help desk staff specifically on vishing and social engineering resistance