OPSEC-MGM-CAESARS-2023
Hospitality · MGM Resorts and Caesars Entertainment
Résumé
In September 2023, two of the biggest names in Las Vegas, MGM Resorts and Caesars Entertainment, were brought to their knees, not by a sophisticated exploit, but by a phone call. The Scattered Spider group simply called the companies' IT help desks, impersonated employees, and talked the support staff into resetting their multi-factor authentication, handing the attackers a way in. From there they deployed ALPHV/BlackCat ransomware. Caesars paid about $15 million; MGM refused and took a roughly $100 million hit as slot machines, hotel keys, and check-in systems went dark for days. It is the lesson that the help desk is part of your attack surface, and that the most advanced MFA is undone by a human who can be convinced to reset it.
How it happened
Scattered Spider (also tracked as UNC3944), an affiliate of the ALPHV/BlackCat ransomware operation, relied on social engineering, specifically vishing (voice phishing) and help-desk manipulation. They researched a target employee, often from public sources like LinkedIn, then phoned the company's IT help desk pretending to be that employee and convinced the support agent to reset the account's password and multi-factor authentication.
That reset was the whole breach. With working credentials and a fresh MFA enrollment, the attackers took over MGM's identity provider itself, gaining super-administrator rights in its Okta tenant and Global Administrator on its Azure AD, which handed them the keys to everything downstream. By the attackers' own account, relayed by researchers and worth treating as a boast, the initial help-desk call took only about ten minutes. They then deployed ransomware: ALPHV claimed it encrypted more than 100 VMware ESXi hypervisors, the machines that run entire data centres of virtual servers, and said it did so only after MGM began pulling systems offline to contain the intrusion. The strongest MFA in the world did not matter, because the attacker never had to defeat it; they had it reset.
The damage
Caesars was breached separately, through a social-engineering attack on an outsourced IT support vendor rather than its own help desk, and had its loyalty-program database stolen, including driver's license and Social Security numbers (though it said it had no evidence that passwords, bank-account, or payment-card data was taken). It reportedly paid roughly $15 million of a $30 million demand and told regulators it had taken steps to ensure the stolen data was deleted, the standard ransom euphemism with no real guarantee. MGM took the opposite path and refused to pay, and still absorbed a roughly $100 million blow, specifically to the September Adjusted Property earnings of its Las Vegas and regional resorts (its one-time incident costs were under $10 million, and it expected insurance to absorb them), with days of outage, slot machines down, digital room keys dead, manual check-in, and the personal data of customers who transacted before March 2019 exposed. The two responses together made an expensive point: refusing to pay avoids funding the attacker, but without preparation it still costs a fortune.
Why MGM still matters
MGM is the help-desk social-engineering lesson. Your MFA is irrelevant if an attacker can phone your help desk and get it reset, because the identity-recovery process is itself an authentication path, and it is often the weakest one. Scattered Spider, young, fluent, native-English social engineers, made this their signature. The defences target the human process: harden help-desk identity verification so a reset requires strong, out-of-band proof and never just a name and employee ID; use phishing-resistant MFA with number matching; treat MFA re-enrollment and help-desk resets as high-risk events worth alerting on; restrict and monitor privileged access; segment the network so one foothold cannot reach the hypervisors; and keep offline backups. It is the same crew behind the Twilio breach. US authorities later codified the lesson: a joint CISA and FBI advisory named Scattered Spider's signature technique as calling IT help desks to impersonate employees and reset MFA. Accountability came slowly but it came: the US charged five alleged members in November 2024, and in August 2025 one of them, Noah Urban, was sentenced to ten years in prison.
Comment le corriger
- Lock down the help-desk reset process immediately (freeze MFA and password resets pending stronger verification), and reset credentials and sessions for affected accounts.
- Isolate and rebuild ransomware-hit systems from offline backups, and rotate all privileged credentials and keys.
- Hunt for the lateral-movement path from the initial reset through the identity provider to the hypervisors, and close it before reconnecting.
Comment l’éviter
- Harden help-desk identity verification: require strong, out-of-band proof before any password or MFA reset, never a name and employee ID alone.
- Use phishing-resistant MFA with number matching, and alert on MFA re-enrollment and help-desk resets as high-risk events.
- Restrict and monitor privileged access (especially identity-provider super-admin roles), and segment the network so one compromised account cannot reach the virtualization layer.
- Keep tested, offline backups and a rehearsed ransomware plan; refusing to pay still costs dearly without them.
- Train help-desk staff specifically against vishing and impersonation, including of third-party vendors, and give them a safe way to escalate suspicious requests.
Références
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a
- https://www.bleepingcomputer.com/news/security/mgm-resorts-ransomware-attack-led-to-100-million-loss-data-theft/
- https://www.sec.gov/Archives/edgar/data/0001590895/000119312523235015/d537840d8k.htm
- https://www.justice.gov/usao-cdca/pr/five-alleged-members-transnational-cybercrime-group-charged-multimillion-dollar-hacking
- https://krebsonsecurity.com/2025/08/sim-swapper-scattered-spider-hacker-gets-10-years/
Vulnérabilités liées
Tout OpSec →- CRITICALOPSEC-MIDNIGHT-BLIZZARD-2024
In January 2024, Microsoft revealed that Russia's foreign-intelligence service, the same APT29 behind SolarWinds, had been reading the email of its senior leadership. The way in was almost insulting in its simplicity: a forgotten, non-production test account with a weak password and no MFA. The attackers guessed the password by spraying common ones across many accounts, then pivoted through a forgotten over-privileged application to grant themselves access to corporate mailboxes, including those of executives and the security and legal teams. It is the lesson that your security is only as strong as the account you forgot about, and that even Microsoft's perimeter fell to a missing MFA checkbox.
- HIGHOPSEC-TWITTER-2020
On 15 July 2020, the Twitter accounts of Barack Obama, Joe Biden, Elon Musk, Bill Gates, Jeff Bezos, and Apple all tweeted the same thing: send Bitcoin and I will send back double. It was a scam, and it ran from inside Twitter. Attackers had phoned a handful of Twitter employees, posed as IT, and talked them out of their credentials, which gave access to an internal admin tool that could take over any account on the platform. The mastermind turned out to be a 17-year-old. It is the lesson that a powerful internal "god-mode" tool is only as secure as the most socially-engineerable employee who can reach it.
- CRITICALOPSEC-SNOWFLAKE-2024
In mid-2024, a single gap, accounts without multi-factor authentication, turned into one of the largest waves of data theft ever, hitting Ticketmaster, AT&T, Santander, and around 165 other companies at once. The attackers never broke Snowflake, the cloud data platform all of them used. They simply logged in with valid usernames and passwords, harvested months or years earlier by infostealer malware from employees' personal computers and bought on criminal markets. Where MFA was not turned on, a stolen password was a full key. It is the defining lesson of the infostealer era: your breach can start on an employee's home laptop, and MFA is the difference between a leaked password and a catastrophe.
- CRITICALOPSEC-23ANDME-2023
23andMe held the most personal data there is: people's DNA. In 2023 attackers got into more than 18,000 accounts and, through a single social feature, turned that into the genetic and ancestry data of roughly 6.9 million people. The break-in required no flaw in 23andMe at all. Attackers simply took username-and-password pairs leaked from other companies' breaches and tried them, betting, correctly, that people reuse passwords. The accounts had no MFA, and 23andMe did not notice the five-month wave of automated logins. From those footholds, the attackers scraped relatives' data through an opt-in feature, and the fallout, fines, a $50 million settlement, and ultimately bankruptcy and a fire-sale of the DNA database itself, shows that a breach can be fatal even when your own systems were never hacked.
- CRITICALOPSEC-LASTPASS-2022
LastPass is a password manager, the digital vault tens of millions of people trusted with every password they have. In 2022 attackers got into it, and the breach unfolded in a way that turned a developer's home computer into a path to those vaults. A first intrusion stole source code. The attackers used it to identify and target one of only four engineers who held the keys to production backups, planting a keylogger on his home PC through an unpatched flaw in, of all things, his Plex media server. With his master password captured, they exfiltrated backups of customers' encrypted password vaults. The encryption held, but anyone with a weak master password was now exposed to offline cracking at the attacker's leisure. It is the lesson that a vault is only as strong as the master password protecting it, and that your blast radius includes your engineers' home machines.
- HIGHOPSEC-UBER-2022
In September 2022, an 18-year-old broke into Uber and posted screenshots of its internal systems to prove it, an embarrassingly total compromise that started with a tactic anyone can fall for: pestering. The attacker, part of the Lapsus$ group, had a contractor's stolen password, and to get past multi-factor authentication, simply spammed the contractor with login-approval prompts until, worn down and then nudged over WhatsApp by the attacker posing as IT, they tapped "approve." Once inside, the attacker found a script with a hardcoded admin password that unlocked Uber's most powerful systems at once. It is the textbook lesson in MFA fatigue, and in how one hardcoded secret turns a foothold into a takeover.