How to verify callers before password resets, and protect your phone number from SIM swaps
The attack that knocked out slot machines and hotel room keys at MGM Resorts in 2023 reportedly began with a phone call to the company's own IT help desk.[1] This guide explains how to check that a caller is who they say they are before anyone resets a password or a second login step, and how individuals can stop a criminal from talking a phone carrier into handing over their number.
Why the help desk is a target
A help desk exists to get people back to work quickly. In a small office, that "help desk" might be the office manager, the owner's nephew who knows computers, or an outside IT company. Whoever it is, they hold a power attackers want: they can reset a password or remove the second login step on an account.
That is why strong multi-factor login is only as strong as the reset process behind it. In a 2023 advisory, the FBI and CISA described a group known as Scattered Spider that poses as IT or help desk staff by phone and text, persuades phone carriers to move a target's number to a SIM card the group controls, and floods employees with login approval prompts until someone accepts.[2] Each of those tricks targets a person trying to be helpful, not a piece of software.
Three cases, one missing check
MGM Resorts, 2023. According to reporting at the time, attackers called MGM's IT service desk while posing as an employee and talked their way into access. A former employee told reporters that staff could get a password reset by giving details such as their name, employee ID and date of birth, the kind of facts that can be pieced together online. Reporting said the attackers then impersonated people with higher-level access and had their multi-factor settings reset.[1] MGM later estimated the attack would cut about $100 million from quarterly earnings.[3] See the MGM help desk call.
Electronic Arts, 2021. The hackers told reporters that after getting into an EA chat workspace, they messaged IT support posing as an employee who had lost a phone at a party, and support issued them a new multi-factor token. They said that let them reach the systems holding game source code.[4] Read the EA lost-phone story.
The SEC's X account, 2024. A man in Alabama used a fake ID at a phone store to get a replacement SIM card for the number linked to the Securities and Exchange Commission's X account, then used it to receive the codes needed to get in. A fake post about bitcoin followed. He pleaded guilty and was sentenced to 14 months in prison.[5] The SEC said multi-factor login on the account had been switched off months earlier.[6] See the SEC SIM swap.
In each case, someone was asked to trust a story, and the process let the story win.
Identifiers are not proof
The core mistake is treating facts about a person as proof that you are talking to that person. A name, date of birth, employee number, last 4 digits of a Social Security number, address or manager's name are identifiers. Many of them sit in old data leaks or on professional networking profiles. Anyone who has done an hour of homework can recite them.
Help desks can also leak these details to each other. In 2012, attackers took over a technology journalist's Apple, Google and Twitter accounts in about an hour by calling Amazon and Apple support and using what one company revealed to satisfy the other's identity check. Both companies changed their rules within days. See the iCloud wipe case.
Proof means the caller controls something only the real person has: the phone number already in your records, the security key registered to their account, or their face matching the photo you have on file, confirmed by someone who knows them.
A caller verification rule for small offices
Write this down, and make sure whoever handles resets, inside or outside the office, follows it every time:
- Hang up and call back. For any reset request by phone, text, chat or email, end the conversation and call the person back on the number already in your staff records. Never use a number the caller gives you.
- Confirm with a second person. For owner, administrator and finance accounts, the person's manager or another partner confirms the request before anything changes.
- Treat multi-factor resets as the highest risk. Removing someone's second login step or registering a new phone for them should require the callback plus a second approval, or an in-person or live video check against a photo you already have.
- Tell the real person. Turn on alerts so staff get an email or text whenever their password or login settings change, and ask them to report any change they did not request.
- Urgency is a warning sign. "I'm about to present to a client" or "the boss needs this now" is a reason to slow down, not speed up.
- Ask your IT provider for its process in writing. Rival casino company Caesars disclosed a similar attack around the same time as MGM, which reporting said came through an outsourced IT support vendor.[1] Our vendor access guide covers what to ask.
The best long-term fix is to make resets rare. Staff who use security keys or passkeys, with a registered spare, seldom need a reset at all. See our MFA guide.
Protecting a phone number from SIM swaps
A SIM swap is when a criminal persuades a phone carrier to move someone's number onto a new SIM card, so their calls and texts, including login codes, go to the criminal. A port-out is the same trick using a transfer to a different carrier. Both depend on a store employee or call center agent believing a story.
New rules help. In late 2023 the Federal Communications Commission adopted rules requiring wireless carriers to use secure methods to confirm a customer's identity before a SIM change or port-out, to notify customers immediately when such a request is made, and to let customers lock their accounts against these changes.[7]
For individuals, including older adults and anyone with savings or crypto:
- Turn on your carrier's account lock or number lock. Ask for any SIM-change or port-out protection they offer, and set an account PIN that is not your birthday or the last digits of your Social Security number.
- Move important accounts off text-message codes. For email, banking and investment accounts, use an authenticator app, a passkey or a security key where offered, and remove your phone number as a recovery method if the service allows.
- Watch for sudden "No service." If your phone loses signal for no reason and you get an unexpected notice about a SIM change, call your carrier from another phone right away.
- Never share a code. No real bank, carrier or tech company will call and ask you to read back a code sent to your phone. Hang up and call the number on the back of your card or on your bill.
For businesses, put the same locks on company phone lines, especially any number used to recover email, banking, domain or social media accounts.
Your caller verification checklist
- A written verification rule. Callback to a known number for every reset request.
- Second approval for sensitive accounts. Owners, admins and anyone who moves money.
- Multi-factor resets get extra checks. Never on a caller's word alone.
- Change alerts are on. Staff hear about any password or login change.
- Your IT provider follows the same rule. Confirmed in writing.
- Carrier locks are on. For business lines and personal numbers that protect important accounts.
- Text-message recovery is removed where possible. On email, banking, domain and social accounts.
Common questions
Isn't calling people back rude or slow?
It takes a minute, and staff get used to it quickly when it applies to everyone, including the owner. Explain it once as a rule that protects everyone's accounts. A real employee locked out before a meeting will be far less inconvenienced by a callback than by an attacker taking over their account.
What if the caller is the boss and is angry?
That pressure is exactly what attackers use. The owner or managing partner should say, in writing, that nobody will ever be in trouble for following the verification rule, including with the owner. Then the answer to an angry caller is simple: "I'll call you right back on your number."
Does the FCC rule mean I no longer need a carrier PIN?
No. The rule requires carriers to use secure identity checks and to offer account locks, but you usually still need to turn the lock on yourself.[7] Ask your carrier what protection it offers, switch it on, and keep your PIN somewhere safe.
Put it in writing
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Employee offboarding checklist: how to cut off a former employee's access the same day
- How to stop fake invoices, changed bank details and fake-boss payment requests
- How a small business keeps software and devices patched, and why default passwords must go
- Backups that survive ransomware: offline copies, tested restores and a one-page plan
- Which two-step login actually stops phishing, and how a small office rolls it out
- How to manage vendor, IT provider and contractor access to your systems
- Cases behind these controls
General guidance, not legal advice. Check requirements specific to your industry with a qualified adviser.
- Digital Insurance (Bloomberg): MGM Resorts hackers broke in after tricking IT service desk
- CISA and FBI: Scattered Spider (Cybersecurity Advisory AA23-320A)
- SEC: MGM Resorts International Form 8-K, October 5, 2023
- CyberScoop: Hackers used Slack to break into EA Games
- U.S. Department of Justice: Alabama Man Sentenced to 14 Months in Connection with SEC X Hack That Spiked Bitcoin Value
- U.S. Securities and Exchange Commission: SEC Statement on @SECGov X Account Compromise
- FCC: Protecting Consumers from SIM Swap and Port-Out Fraud (Report and Order, adopted 2023)