top of page

MGM Resorts Breach 2023: Help Desk Social Engineering and Operational Risk

Oct 10, 2023
4 min read

Updated: Aug 31

The MGM Resorts attack reportedly began with LinkedIn research and a call to the IT help desk, and ended in days of widespread operational disruption. Whatever verification process stood between the caller and account recovery, the reported attack found a way through it.


Case type: Social engineering / help desk impersonation

Identified: Sept 10, 2023   Disclosed: Sept 11, 2023

Attribution: Scattered Spider (UNC3944); ALPHV/BlackCat ransomware



Many people imagine cyberattacks as highly technical operations involving sophisticated malware, advanced exploits, and complex attacks against infrastructure. The 2023 MGM Resorts breach tells a different story.


According to public reporting, the attack began with social engineering and identity manipulation rather than a technical vulnerability, and it ended with disrupted hotel operations, casino systems, reservations, and digital services across one of the world's largest hospitality organizations. Attackers do not always need to hack their way into an organization. Sometimes they convince someone to let them in.




The attack reportedly started with research, not malware. According to reporting based on claims from the attackers, the group identified an MGM employee through LinkedIn and used social engineering against the company's IT help desk to obtain access. Public reporting has described the interaction as a short call, but MGM has not publicly documented the precise help-desk exchange or account-recovery steps that enabled the initial compromise. Subsequent reporting indicated that the attackers gained extensive access within MGM's identity and cloud environments.


MGM's security team detected the intrusion on September 10 and began shutting down affected systems to contain it, which is when the visible chaos started: MGM's decision to shut down certain systems to contain the incident produced widespread operational disruption across its U.S. properties, affecting digital services and customer-facing operations. MGM publicly disclosed the incident on September 11. The attackers later claimed that ransomware associated with ALPHV/BlackCat had been deployed against MGM's ESXi infrastructure.



Over the following days, the picture got worse before it got better. The attackers claimed on September 14 to have stolen six terabytes of MGM's data, the same day MGM began restoring its systems. On September 18, Okta itself confirmed that MGM was one of at least five of its customers targeted using the same help-desk social engineering pattern, meaning this wasn't a one-off improvisation but a repeatable technique being run against multiple organizations. By early October, MGM reported that operations at its domestic properties had returned to normal and that virtually all guest-facing systems had been restored. In an October 5 securities filing, MGM estimated an approximately $100 million negative impact to Adjusted Property EBITDAR for its Las Vegas Strip Resorts and Regional Operations. The company also confirmed that customer personal data had been stolen, including names, contact details, dates of birth, and, for some customers, driver's license, Social Security, or passport numbers.




The resulting disruption reached far beyond IT, affecting:







Attackers target processes, not just technology


Organizations may invest heavily in firewalls, endpoint protection, monitoring tools, and cloud security controls. Every organization also relies on people making decisions and following procedures, and when an attacker successfully manipulates an identity or access process, they may circumvent controls that depend on that process. The question that mattered at MGM was whether the process designed to verify identity could withstand deliberate deception under pressure. In this case, the reported social-engineering attack succeeded in obtaining access.


The attackers never needed to hack their way in. They convinced someone to let them in.



Built for speed, tested by deception


Help desks exist to solve problems and help users regain access when issues occur. That mission makes them valuable targets. Help desk personnel are often under pressure to:



These goals are important, and they create openings. A convincing attacker exploits:



The more pressure placed on employees to solve problems quickly, the greater the risk that verification procedures become shortcuts rather than safeguards.




Verification is a security control, not paperwork


Organizations often treat identity verification as an administrative task. The MGM incident shows it should be treated as a security control. Verification determines whether someone is who they claim to be, and if an attacker can pass for an employee, they gain access without ever compromising a password, exploiting software, or touching a technical defense. Effective verification procedures should be:



Most importantly, employees must feel empowered to follow procedures even when doing so creates inconvenience. A delayed access request is usually far less costly than a successful compromise. MGM learned that math the hard way:






Not one decision. A set of conditions.


The question organizations should ask isn't "why did the help desk reset the account?" A more useful question is: what conditions made that reset possible, and what turned one reset into ten days of disruption?





Pausing to verify has to beat speed


Security culture is reflected in everyday decisions. Do employees feel comfortable challenging unusual requests? Are verification procedures consistently followed? Is security viewed as everyone's responsibility? Do employees prioritize validation over convenience?


Strong cultures encourage employees to pause and verify. Weak cultures reward speed and convenience at the expense of caution, and attackers look for organizations where bypassing a process is easier than following it.




Cyber incidents are operational incidents


One of the most important lessons from the MGM incident is that the attack affected business functions customers rely on every day. Operational disruption creates consequences such as:



Many organizations focus on preventing data loss while overlooking operational resilience. An inability to deliver services can be just as damaging as the loss of information, and at MGM the two arrived together.








"A Process Is a Security Control."


The MGM breach is usually told as a ransomware story, and ransomware was how it ended. It started as a process story: trust, identity, and a successful social-engineering interaction created the path to access long before ransomware entered the picture.


As organizations strengthen technical defenses, the processes wrapped around identity deserve the same rigor: help desk verification, reset procedures, escalation paths, and a culture where pausing to verify is rewarded rather than punished.


BECAUSE SOME OF THE MOST EXPENSIVE BREACHES BEGIN WITH A SIMPLE QUESTION, A CONVINCING STORY, AND TRUST PLACED IN THE WRONG PERSON.


Sources


Comments


bottom of page