How the MGM Resorts cyberattack happened: the help desk call that cost $100 million
The attack that knocked out slot machines and hotel room keys across MGM Resorts' Las Vegas properties in September 2023 reportedly started with a phone call to the company's own IT help desk.[3] This case file covers what happened, how a convincing caller got past the front line, what it cost, and the one control that would have stopped it.
What happened
On September 11, 2023, MGM Resorts discovered a cyberattack on its systems.[2] To keep the intruders from going further, the company shut systems down, and guests felt it immediately. Slot machines, restaurant systems, room key cards, booking tools and ATMs at properties including the MGM Grand, Mandalay Bay, Bellagio and Aria were knocked out of service for days.[2][5] MGM announced the incident publicly on September 12.[1]
Within days, reporting said the way in had been a social engineering call to MGM's IT service desk. The ransomware gang known as ALPHV, or BlackCat, claimed responsibility, and reporting tied the intrusion to a loose hacking group known as Scattered Spider, with members in the US and UK, that sometimes works with that gang.[2][3][4]
MGM did not pay a ransom.[6] In an October 5, 2023 filing with the Securities and Exchange Commission, the company said operations at its domestic properties had returned to normal and that customer data had been taken.[1][2] Around the same time, rival Caesars Entertainment disclosed a similar attack, which reporting said came through an outsourced IT support vendor.[3]
How they got in
A help desk exists to get stuck employees back to work quickly. That is exactly what makes it a target. According to reporting at the time, attackers contacted MGM's IT service desk while posing as an employee and talked their way into access.[3]
A former MGM employee told reporters that staff could get a password reset by giving basic details such as their name, employee ID number and date of birth.[3] Details like those are not secrets. They can often be pieced together from professional networking profiles, old data leaks or a bit of patient research.
Once inside, reporting said the attackers moved on to impersonating people with higher-level access and resetting the multi-factor authentication (the second login step, such as a code on a phone) tied to those accounts.[3] The identity provider Okta had warned its customers in August 2023 about this same pattern: callers targeting help desks to get multi-factor protections reset on powerful accounts.[3][4] In other words, the strongest lock on the door was only as strong as the person who could be talked into removing it.
What it cost
In its SEC filing, MGM estimated the attack would cut about $100 million from its third-quarter adjusted property earnings (a measure of operating profit before certain costs) across its Las Vegas Strip and regional operations. It also reported less than $10 million in one-time costs for consultants, lawyers and other advisers, and said it expected cyber insurance to cover the financial hit.[1]
The data loss affected some customers who had done business with MGM before March 2019. Stolen details included names, contact information, gender, dates of birth and driver's license numbers, and for a limited number of people, Social Security and passport numbers. MGM said no customer passwords, bank account numbers or payment card data were taken.[1]
In January 2025, MGM agreed to pay $45 million to settle class action lawsuits over both the 2023 attack and an earlier 2019 breach, which together exposed information on more than 37 million customers.[5]
On July 18, 2024, UK police working with the National Crime Agency and the FBI arrested a 17-year-old in Walsall, England, in connection with the attack as part of a wider investigation into the group.[6] This page does not name him.
The missing control
The missing control: strong identity verification at the help desk. Before resetting a password or a second login factor, the help desk needed proof that the caller really was the account owner, using something an outsider could not look up or guess.
Name, employee number and birth date are identifiers, not proof. A reset process that requires a callback to a phone number already on file, a video check against the employee's badge photo, or approval from the employee's manager would have forced the caller to control something only the real employee has. Extra checks for accounts with administrator powers would have mattered most, because those were the keys that let a single call turn into a company-wide outage.[3]
What to do in your business
- Write down how you verify a caller. Whoever handles password resets, whether an employee or an IT contractor, should follow a written rule that does not rely on facts anyone could find online.
- Call back on a known number. When someone asks for a reset, hang up and call them back on the number already in your records, not the one they give you.
- Treat multi-factor resets as high risk. Removing someone's second login step should need a second person's approval, especially for owner and administrator accounts.
- Ask your IT provider how they do it. If you outsource support, ask them to describe their reset process in writing. Caesars' attack reportedly came through an outside IT vendor.[3]
- Alert the real person. Set accounts to send a notice by email or text whenever a password or multi-factor setting changes, so an employee can flag a reset they never asked for.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: Employee offboarding checklist: how to cut off a former employee's access the same day
- Guide: How to verify callers before password resets, and protect your phone number from SIM swaps
- Guide: Which two-step login actually stops phishing, and how a small office rolls it out
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- How the 2020 Twitter hack happened: a fake help desk call and an admin tool
- How the Mirai botnet knocked Twitter and Netflix offline with factory passwords
- How the Ronin bridge was hacked: a fake job offer and $600 million
- How Uber got hacked in 2022: a stolen password and one tired tap
- Every identity and access control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- SEC: MGM Resorts International Form 8-K, October 5, 2023
- The Record: MGM Resorts cyberattack cost millions
- Digital Insurance (Bloomberg): MGM Resorts hackers broke in after tricking IT service desk
- TechTarget: MGM faces $100M loss from ransomware attack
- The Record: MGM agrees to $45 million payment to data breach and ransomware victims
- The Record: Teenage suspect in MGM Resorts hack arrested in Britain