MGM Resorts and Scattered Spider (Sept 2023): A Help Desk Call That Cost $100 Million
Facts in this article were checked against the sources listed below as of Oct 5, 2026.
Retrospective: this article looks back at events from September 2023, written in 2026 with the benefit of hindsight.
On September 12, 2023, MGM Resorts International disclosed a cybersecurity issue that disrupted operations across its properties. Slot machines went dark, digital room keys stopped working and reservations moved to paper. MGM confirmed a return to normal operations on September 20, after roughly ten days of disruption.
- ReconnaissanceAttackers find an MGM employee's details on LinkedIn, according to claims made to researchers.
- Help desk callA short vishing call impersonating the employee persuades IT support to help with account access.
- Identity takeoverThe attackers gain administrative access to MGM's Okta and Azure environments, according to reporting.
- RansomwareScattered Spider, working with ALPHV/BlackCat, disrupts systems across MGM properties.
- ImpactAbout ten days of disruption; MGM's 8-K estimates roughly $100 million impact on adjusted property EBITDAR.
In an 8-K filing on October 5, 2023, MGM estimated about $100 million of impact to adjusted property EBITDAR, plus less than $10 million in one-time expenses, and confirmed that customer personal data had been obtained. The attack has been widely attributed to Scattered Spider, working with the ALPHV/BlackCat ransomware operation.
The entry point, according to claims the attackers made and subsequent reporting, wasn't malware or a zero-day. It was a phone call.
What happened
Scattered Spider claimed it found an MGM employee on LinkedIn and called the IT help desk while impersonating that person. Reporting described a short vishing call that persuaded support staff to help with account access. From there, the attackers obtained administrative access to MGM's identity environment — reported to include its Okta and Azure tenants — and used it to expand control and deploy ransomware.
Around the same time, Caesars Entertainment disclosed a similar attack by the same group.
How help-desk social engineering works
Help desks exist to restore access quickly. That's their job — and it's what attackers exploit:
- Research: names, roles, managers and employee IDs are often discoverable through LinkedIn, data breaches and social media.
- Pretext: "I'm traveling and lost my phone; I need my MFA reset before a meeting."
- Urgency and confidence: fluent, native-sounding callers who know internal terminology.
- Target selection: IT staff and administrators, whose accounts unlock the most.
Once an attacker controls a privileged identity, the identity provider itself becomes the weapon: new MFA devices, new admin assignments, federation changes and access to every connected application.
Why it mattered
The help desk is part of your security perimeter. A process designed for convenience became the front door for a nine-figure incident.
Identity infrastructure was the real target. Control of Okta and Azure administration meant control of access to nearly everything else.
The playbook kept working. Scattered Spider was linked to the 2025 attacks on UK retailers including Marks & Spencer, which followed a strikingly similar pattern through a third-party service desk.
What to do now
- Classify reset requests by risk. A password reset for a standard user, an MFA reset, and anything touching an administrator or executive should follow different procedures.
- Retire knowledge-based verification. Date of birth, employee ID, manager's name and the last four digits of a Social Security number can be found or bought. Instead, push a verification request to a method the user already has registered, call back on a number already on file (never one the caller provides), use video verification against an ID photo or manager confirmation through a separate channel, or use Microsoft Entra Verified ID with face check for high-assurance identity proofing.
- Issue a Temporary Access Pass instead of deleting MFA methods. After verification, a time-limited, single-use pass lets the user register new methods themselves.
- Add friction for privileged accounts. Require two people, or security approval, to reset admin and executive accounts. Use restricted management administrative units so the help desk can't reset them at all.
- Protect MFA registration with Conditional Access. Require a compliant device, trusted location or Temporary Access Pass to register new security information.
- Use phishing-resistant MFA for administrators. Passkeys and FIDO2 keys limit what an attacker can do even after a successful reset.
- Alert on the pattern. MFA method changes followed by sign-ins from new devices or locations, and any reset of a privileged account, should page someone.
- Hold outsourced providers to the same standard — and test them.
How to detect help-desk social engineering
The attack happens on the phone, but its consequences appear in identity logs within minutes:
- MFA changes followed by new sign-ins. In Entra ID audit logs, events such as "Admin deleted security info," "Admin registered security info" or "Create Temporary Access Pass method for user," followed within a few hours by a successful sign-in from a new device, IP address or country, are a strong signal.
- Privileged actions soon after a reset. Role activations, Conditional Access changes, new federation settings or new app credentials by an account that was just reset should page your on-call responder.
- Resets without tickets. Correlate help desk actions with your ticketing system. A reset with no matching ticket is worth a call to the help desk agent.
- Identity provider admin activity. If you use Okta or another IdP alongside Entra ID, stream its admin logs to your SIEM too.
Common mistakes
- Training only the help desk. Social engineers also call employees pretending to be IT. Everyone should know that IT will never ask for codes or for approval of an MFA prompt.
- Outsourcing verification without oversight. Third-party service desks need your procedures and your testing.
- Treating executives as exceptions. Executives often push for faster resets — which is exactly why attackers impersonate them.
- No recovery plan for identity. If attackers control your identity provider, you need break-glass access and a tested plan to regain control.
What happened next
Scattered Spider didn't stop with casinos. In 2025, the group was linked to attacks on UK retailers, including Marks & Spencer, which said attackers entered through human error at a third party and expected about £300 million in lost operating profit. The lesson is that help desk hardening isn't a one-off project. It needs regular testing, including any outsourced service desk.
Questions for leadership
- How does our help desk — including any outsourced provider — verify a caller before resetting MFA?
- Is resetting an administrator's account harder than resetting anyone else's?
- When did we last test the help desk with a simulated social engineering call?
Key takeaways
- MGM's disruption reportedly began with a help-desk phone call and cost about $100 million in earnings impact.
- Attackers targeted identity administration, not just a single user.
- Verification that relies on personal details is no longer adequate.
- Temporary Access Pass, phishing-resistant MFA and protected registration limit the damage of a single successful call.