Skip to content
Security Notes

MGM Resorts: a ten-minute help desk call versus the security stack

By Elias Lankinen10 min read

The ten-minute phone call

On September 11, 2023, guests at some of the most profitable hotels on the Las Vegas Strip found themselves standing outside their own rooms. Digital key cards had stopped working. Slot machines went dark, roped off in long silent rows. Restaurant point-of-sale terminals could not take a payment, the MGM Rewards app would not load, and check-in lines curled through casino lobbies while staff scribbled reservations on paper. This was MGM Resorts International, a company that at the time carried a market value north of $33 billion, grinding to a near halt across properties from the Bellagio to the MGM Grand to Mandalay Bay. The people responsible later explained how they did it, and the explanation is the most unsettling part of the whole story. According to a widely circulated statement posted by the malware-research collective vx-underground and reported by Engadget, all it took was this: hop on LinkedIn, find the name of an MGM employee, then call the company's IT help desk and pretend to be that person. "A company valued at $33,900,000,000 was defeated by a 10-minute conversation," the group wrote.

Source: Wikimedia Commons, photo by Nadavspi
Source: Wikimedia Commons, photo by Nadavspi

That figure is the attackers' own boast, and boasts from criminals deserve scrutiny. But the mechanism they described is real, corroborated by security vendors, federal advisories, and MGM's own regulatory filings. It is worth sitting with, because it inverts almost everything a casual observer assumes about how big companies get hacked. There was no zero-day exploit, no dazzling piece of custom malware, no brute-forced password. There was a phone call, and a help desk employee who wanted to be helpful.

The phone call that beat the firewall

The technique has a name: vishing, short for voice phishing. Instead of sending a fraudulent email and hoping the target clicks, the attacker calls a human being and manipulates them in real time. The group behind the MGM intrusion, known as Scattered Spider, has turned this into an assembly-line process. Here is how it works, according to the joint advisory published by the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) in November 2023. The attackers first do reconnaissance on public sources like LinkedIn to identify a real employee: their name, job title, and enough context to sound authentic. Then they call the corporate IT help desk posing as that employee, typically claiming to be locked out. They ask the help desk to reset the account password and, crucially, to re-enroll or reset the multi-factor authentication (MFA), the second login step, usually a code or push notification, that is supposed to stop exactly this kind of takeover. The reset is the whole game. MFA is designed on the assumption that even if an attacker steals your password, they cannot produce the second factor tied to your phone. But if you can convince a help desk to point that second factor at your device instead, the protection evaporates. The advisory notes that Scattered Spider will "pose as company IT and/or helpdesk staff" and also work the other direction, calling employees to trick them into surrendering a one-time code, or bombarding them with repeated MFA prompts until, worn down, they tap "approve." That last trick has its own name, MFA fatigue. Help desks are uniquely vulnerable to this because their entire job is to unblock frustrated employees quickly. A support agent who demands too much proof of identity generates complaints; one who resets a password on a plausible-sounding call gets a good performance review. The attackers exploit that incentive. They are calm, they know the employee's details, and they apply gentle pressure. Ten minutes is plausible.

Source: Wikimedia Commons, photo by Silentobserver1
Source: Wikimedia Commons, photo by Silentobserver1

The identity layer was the real front door

Getting one employee's credentials would normally give an attacker a foothold, not the keys to the kingdom. What made the MGM and Caesars intrusions so devastating was whose account they targeted and what that account controlled: the company's identity provider, the system that decides who is allowed into every other system. MGM used Okta, a widely deployed platform that handles single sign-on, the arrangement where one login grants access to dozens of downstream applications. On August 31, 2023, just before the casino attacks became public, Okta itself published a security advisory describing a "cross-tenant impersonation" campaign against several of its US customers. The technique is worth unpacking, because it shows the attackers were not merely lucky, they understood the plumbing. Once Scattered Spider socially engineered their way to high privileges, they abused a feature called inbound federation, sometimes labeled "Org2Org." Federation lets one organization's identity system trust another's, so that, say, a company and an acquired subsidiary can share logins. The attackers stood up a second identity provider that they controlled, then configured MGM's Okta to trust it. By setting the username field in their rogue provider to match a real MGM user, they could sign in through the back door as that user, into whatever applications the target could reach. This step, Okta noted, required Super Administrator or Org Administrator permissions, the very highest level, which is precisely what the help desk reset had handed them. The distinction that matters here is between the network perimeter, the firewalls and VPNs everyone pictures, and the identity perimeter. Modern enterprises no longer live behind a single wall. Their data sits in cloud services reachable from anywhere, and the thing standing between an attacker and that data is identity: proof that you are who you claim to be. Scattered Spider didn't break through a wall. They talked their way into becoming the gatekeeper.

What actually broke

When MGM's security team detected the intrusion, they did the textbook thing and started shutting systems down to contain it. That defensive move is itself what guests experienced as chaos. Take the identity system offline and every dependent service, key cards, slot machines, reservation databases, the loyalty app, corporate email, goes down with it. The Washington Post reported that room keys stopped working, dinner reservations vanished, payment terminals failed, and whole sections of slot machines sat idle. Employees were locked out of email for days. Staff reverted to handwritten receipts and manual check-ins. The disruption stretched across roughly ten days before operations approached normal in early October, and MGM said September occupancy on the Strip fell to 88 percent from 93 percent a year earlier. Of the company's Las Vegas properties, essentially only the Cosmopolitan escaped, having been on separate systems following its recent acquisition.

Source: Wikimedia Commons, photo by David Vasquez
Source: Wikimedia Commons, photo by David Vasquez

In an 8-K filing with the Securities and Exchange Commission on October 5, 2023, MGM put a number on the damage: an estimated $100 million negative impact on Adjusted Property EBITDAR, a core measure of casino profitability, for the third quarter, plus less than $10 million in one-time costs for consultants, legal advisers, and cleanup. The company also disclosed that the attackers had obtained personal data belonging to customers who transacted with MGM before March 2019, including names, contact details, dates of birth, and driver's license numbers, and for a smaller set of people, Social Security and passport numbers. Payment card data, MGM said, was not taken.

Two casinos, two very different choices

The MGM story is inseparable from a second one that unfolded days earlier and mostly out of public view. Caesars Entertainment, MGM's chief rival, had been hit by the same crew using the same method: social-engineering a third-party IT vendor to reach Caesars' identity systems. According to Infosecurity Magazine, the attackers made off with a six-terabyte copy of the Caesars loyalty database covering tens of millions of rewards members. Caesars made a different decision than MGM. Faced with a reported $30 million extortion demand, it negotiated and, per multiple reports, paid roughly $15 million to keep the stolen data from being leaked. Because it paid quickly and quietly, Caesars largely avoided the operational meltdown that engulfed MGM. Its casino floors kept humming. MGM refused to pay. The attackers, who by then were partnering with a Russia-linked ransomware-as-a-service operation called ALPHV/BlackCat, deployed ransomware against MGM's infrastructure, reportedly encrypting a large number of the company's virtual servers. The two companies illustrate the brutal math of a ransomware decision. Caesars spent $15 million and stayed open; MGM spent nothing on ransom and absorbed a $100 million hit plus reputational damage and a wave of class-action lawsuits. Neither outcome is a clean win. Paying funds the criminal ecosystem and offers no guarantee, and the FBI, working with the blockchain-analysis firm Chainalysis, was later able to trace and freeze a chunk of the crypto Caesars sent when the attackers tried to launder it. Refusing preserves principle and denies the criminals their payout, but the bill still comes.

The misconception worth correcting

The instinctive assumption about a nine-figure casino hack is that it must have involved something exotic: a nation-state, a genius coder, malware no antivirus had ever seen. The MGM case is valuable precisely because it wasn't any of that. The most advanced technical step, the Okta federation abuse, was clever but well documented; the entry point was a telephone. That matters because it reframes who the adversary is. Scattered Spider is not a shadowy foreign intelligence unit. Investigators describe it as a loose, mostly English-speaking group of young men and teenagers in the United States and Britain, drawn from an online subculture known as "The Com" (or "The Comm"), where members trade social-engineering techniques over Discord and Telegram. CyberScoop and Cybersecurity Dive have documented how the collective weaponizes fluent, native-English phone manner, the one thing many foreign cybercrime crews lack, to sail past help desks that would flag a stilted or accented caller. The group operates under a confusing pile of names assigned by different security firms: UNC3944, 0ktapus, Octo Tempest, Muddled Libra, Scatter Swine, Storm-0875. The aliases reflect how many companies they hit before and after the casinos, among them Twilio, LastPass, DoorDash, and Mailchimp. Their advantage was never technical firepower. It was understanding that the weakest link in a hardened enterprise is the human process wrapped around its strongest security controls.

What $100 million bought, and what it didn't

MGM's money and public embarrassment did eventually translate into consequences for some of the people involved, though slowly. In November 2024, US prosecutors indicted five alleged Scattered Spider members. One of them, 20-year-old Noah Michael Urban of Palm Coast, Florida, who used handles including "King Bob" and "Sosa," was sentenced in August 2025 to ten years in federal prison and ordered to pay $13 million in restitution, exceeding what prosecutors had asked for. In September 2025, US authorities charged a 19-year-old British national, Thalha Jubair, as an alleged core member tied to scores of intrusions. UK police had arrested a 17-year-old in 2024 in connection with the MGM attack. But arrests of a handful of individuals have not shut down the model, because the model is a technique, not a person. CISA has repeatedly updated its Scattered Spider advisory, most recently on July 29, 2025, to add new tradecraft: deploying DragonForce ransomware against VMware ESXi servers, and hunting for access to cloud data warehouses like Snowflake to siphon out huge volumes of records in a single burst. The help-desk playbook that beat MGM is now standard operating procedure across a whole cohort of attackers, and it has kept working against major companies well into 2025, including a high-profile wave against British retailers. The defenses are not mysterious, which is the frustrating part. Help desks can require callers to verify identity through something harder to fake than a name and a job title: a manager's approval, a video call, a one-time code sent to a pre-registered device, or in-person confirmation for privileged resets. Phishing-resistant MFA, such as hardware security keys, is far harder to socially engineer than a code read aloud over the phone. Companies can restrict who holds Super Administrator rights and monitor for the creation of new identity-federation relationships, the exact move that turned a single compromised account into total control. The open question is whether organizations will actually pay for that friction. Every one of those controls slows an employee down and irritates someone who just wants back into their account. MGM's $100 million is a reminder that the friction is cheaper than the alternative, but the incentive to skip it never really goes away, and the next call is already coming in. The uncomfortable lesson of the ten-minute conversation is that the most expensive vulnerability in a modern company may not be in its code at all. It is in the entirely reasonable human desire to help.


Sources

  1. Engadget, "Hackers claim it only took a 10-minute phone call to shut down MGM Resorts", 2023
  2. Cybersecurity and Infrastructure Security Agency (CISA) and FBI, "Scattered Spider" (Advisory AA23-320A), 2023, revised 2025
  3. Okta Security, "Cross-Tenant Impersonation: Prevention and Detection", 2023
  4. The Record (Recorded Future News), "MGM Resorts says cyberattack cost $100 million, resulted in theft of customer info", 2023
  5. The Washington Post, "Las Vegas casino hacks: What tourists should know about MGM cyberattack", 2023
  6. Infosecurity Magazine, "Caesars Entertainment Reveals Major Ransomware Breach", 2023
  7. Chainalysis, "How Chainalysis Helped the FBI Track Down and Freeze Millions in the Caesars Casino Ransomware Attack", 2023
  8. CyberScoop, "Florida man gets 10 years in prison in first Scattered Spider sentencing", 2025
  9. CyberScoop, "Scattered Spider weaves web of social-engineered destruction", 2023
  10. Cybersecurity Dive, "What we know about the cybercrime group Scattered Spider", 2024
  11. TechCrunch, "US government charges British teenager accused of at least 120 Scattered Spider hacks", 2025
  12. US Securities and Exchange Commission, MGM Resorts International Form 10-K, FY2023, 2024