GoFirm
Back to Blog
Case Studies·3 min read

How a Teenager Brought Down MGM Resorts and What Should Have Stopped It

By GoFirm

In September 2023, a member of the hacking group Scattered Spider spent ten minutes on the phone with MGM Resorts' IT help desk. They had found an MGM employee on LinkedIn, researched enough to sound credible, and called in claiming to be locked out of their account. The help desk reset the credentials and handed over access.

That single call gave the attackers a foothold in MGM's Okta identity platform. From there they escalated to super administrator privileges across MGM's Azure environment. From there they deployed ransomware across more than 100 ESXi hypervisors. Slot machines went offline. ATMs stopped working. Digital room keys failed. Online booking collapsed across 30 properties. MGM reported $100 million in losses in its third-quarter 2023 results.

The perimeter was bypassed entirely - not through a zero-day exploit or a sophisticated technical attack, but through a conversation. Scattered Spider did not hack in. They were let in.

What followed was a sequence of high-consequence, irreversible infrastructure actions - privilege escalation, administrator access to cloud environments, mass server encryption - none of which required a confirmed decision from a named human authority before they executed. The attackers moved through MGM's systems with the same access rights as a legitimate administrator, because as far as every technical control could tell, they were one.

MGM had MFA in place. They had Okta. They had a security operations team. None of it was sufficient once a social engineering call had produced a valid credential reset. The technical controls were downstream of the problem.

GoFirm operates at the execution boundary itself. The escalation to super administrator privileges that enabled this attack is exactly the class of action GoFirm is configured to gate. Before any privileged access escalation executes, the named authority - a designated administrator, a security lead, whoever the organisation has assigned - receives a confirmation request on their registered personal device, with full context of what is being requested and by whom. They confirm with their biometric or the escalation does not proceed.

A social engineering call to a help desk produces a credential reset. It does not produce a biometric confirmation from a named authority on a registered hardware-bound device. That is the gap between what MGM had and what would have stopped this.

The ten-minute phone call is not an anomaly. Scattered Spider used the same technique against Caesars Entertainment in the same period, prompting a reported $15 million ransom payment. Social engineering of help desks and identity systems remains one of the most reliable attack vectors in enterprise security precisely because the execution boundary has no confirmed authority requirement. GoFirm puts one there.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto’s AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in minutes, not months.

References

1. Netwrix, An Overview of the MGM Cyber Attack, 2024

2. BleepingComputer, MGM Resorts Ransomware Attack Led to $100 Million Loss, Data Theft, October 2023

3. Specops Software, MGM Resorts: How Attackers Hit the Jackpot with Service Desk Social Engineering, 2025

Share this article