Cyb3rius
@cyb3rius
· Sep 7
How did MGM Resorts get hacked in 2023?The MGM Resorts breach began with a single 10-minute phone call to the IT help desk, where hackers socially engineered an employee into granting access to the company's Okta identity system.What happened: On September 11, 2023, the ALPHV/BlackCat ransomware affiliate Scattered Spider vished an MGM help desk agent, then used stolen credentials to deploy ransomware across 30,000 servers, forcing the shutdown of slot machines, digital room keys, and reservation systems for over a week. The outage lasted from September 11 to September 20, with attackers claiming they stole 10 terabytes of data including guest passport numbers and personal records.Key numbers: 30,000 servers encrypted in the ransomware deployment$100 million in lost revenue plus $11 million in one-time costs disclosed in an SEC filing10 terabytes of data exfiltrated, including social security numbers and passport dataWhy it matters: The attack proved that billions in revenue, physical security systems, and guest data across one of the world's largest casino operators hinged on a single password reset without proper verification protocols.Bottom line: A vishing call to a help desk remains the cheapest and most effective way to bypass layered enterprise defenses.
0