CIO Brief: Social Engineering the Help Desk Is the New Ransomware Entry Point
Retrospective: this article looks back at events from September 2023, written in 2026 with the benefit of hindsight.
The short version: In 2023, a phone call to MGM's IT help desk reportedly led to a ransomware attack that shut down casinos and hotels for days and cost about $100 million. The help desk is now one of the most important — and most targeted — security functions in any company.
Why help desks are targeted
Help desk staff are trained to be helpful and fast. Attackers impersonate employees, use details found online, create urgency and ask for a password or MFA reset. One successful call can open the door to the whole company.
The business impact
- Operational shutdown from ransomware.
- Massive financial loss — MGM's estimate was around $100 million.
- Reputational damage with customers.
Questions to ask your team
- How does our help desk verify a caller before resetting a password or MFA?
- Is it harder to reset an executive's or administrator's account than a regular employee's?
- Have we tested our help desk with a simulated social engineering call?
- If our help desk is outsourced, does the provider follow our verification rules?
What good looks like
Verification that can't be passed with publicly available information, stronger checks for privileged and executive accounts, alerts on sensitive resets, and regular testing.
The decision
Commission a social engineering test of your help desk this year. The results are usually eye-opening — and the fixes are mostly process changes, not expensive technology.
- MGM Resorts and Scattered Spider (Sept 2023): A Help Desk Call That Cost $100 Million Incident Teardowns
- How to Harden Help Desk Identity Verification and Password Resets How-To & Hardening
- Detecting Help Desk Social Engineering: Entra Sign-In Logs and Sentinel KQL Detection & Response