Entra ID & IdentityCIO BriefingsRetrospectives

CIO Brief: Social Engineering the Help Desk Is the New Ransomware Entry Point

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from September 2023, written in 2026 with the benefit of hindsight.

The short version: In 2023, a phone call to MGM's IT help desk reportedly led to a ransomware attack that shut down casinos and hotels for days and cost about $100 million. The help desk is now one of the most important — and most targeted — security functions in any company.

Why help desks are targeted

Help desk staff are trained to be helpful and fast. Attackers impersonate employees, use details found online, create urgency and ask for a password or MFA reset. One successful call can open the door to the whole company.

The business impact

  • Operational shutdown from ransomware.
  • Massive financial loss — MGM's estimate was around $100 million.
  • Reputational damage with customers.

Questions to ask your team

  • How does our help desk verify a caller before resetting a password or MFA?
  • Is it harder to reset an executive's or administrator's account than a regular employee's?
  • Have we tested our help desk with a simulated social engineering call?
  • If our help desk is outsourced, does the provider follow our verification rules?

What good looks like

Verification that can't be passed with publicly available information, stronger checks for privileged and executive accounts, alerts on sensitive resets, and regular testing.

The decision

Commission a social engineering test of your help desk this year. The results are usually eye-opening — and the fixes are mostly process changes, not expensive technology.

mgm cyber attack impactMGM / Scattered Spider2023

More on this story