Four attacks. One playbook.
Real cyberattacks on Las Vegas–area businesses, broken down step by step. Pick a case to see the timeline, the technique, and what a small business can learn from it.
Pick a case.
MGM Resorts International
A 10-minute phone call to the IT help desk shut down slot machines, hotel keys, and booking systems for more than 36 hours. MGM chose not to pay, and absorbed the cost of rebuilding instead.
Caesars Entertainment
Compromised through a vendor's help desk. Loyalty-program data exfiltrated. Caesars went the other way and reportedly paid. The stolen data was already gone either way.
Findlay Automotive Group: Direct Breach
Henderson-headquartered dealership chain breached directly. 30+ dealerships across 5 states. Customer + employee PII exposed. Class-action lawsuits in Clark County.
Findlay Automotive via CDK Global: Supply Chain
Two weeks after the direct breach, Findlay's software vendor CDK Global was ransomed. ~15,000 dealers nationwide reverted to pen and paper for ~2 weeks.
Scattered Spider, a loose collective of young, English-speaking operators.
Scattered Spider is not a traditional ransomware crew. It is a fluid set of operators (many in their late teens and early twenties) who meet through gaming platforms, Discord, and Telegram channels that researchers loosely call “the Com.”
Their edge isn't a novel exploit. It is fluent English, a calm phone voice, and the patience to research one employee until they can convince an IT help desk they're that employee. They are responsible for three of the four cases above (MGM, Caesars, and the alleged direct Findlay breach).
- UNC3944 (Mandiant)
- Octo Tempest (Microsoft)
- 0ktapus
- Scatter Swine
- Muddled Libra (Unit 42)
- Star Fraud
Distributed across the US and UK. Several members have been publicly identified.
Conspiracy to commit wire fraud, identity theft, and aggravated identity theft.
Arrested at Palma airport; US filed wire fraud and aggravated identity theft charges.
DOJ unsealed charges against Ahmed Elbadawy, Noah Urban, Evans Osiebo, Joel Evans, and Tyler Buchanan for a wire-fraud conspiracy.
Sources: DOJ press releases, Reuters, Bloomberg, KrebsOnSecurity. Charges do not equal conviction; individuals named are not assumed guilty.
The eight-step playbook. No zero-day required.
1. Reconnaissance on LinkedIn
Identify an IT or help-desk staff member at the target: name, role, manager, badge style, internal jargon.
2. Vish the help desk
Call IT pretending to be the employee. Calm voice, correct context, ask for a password and MFA reset.
3. Reset MFA, log in
Help desk resets MFA. Operator enrolls their own device. Now they log in as the real employee.
4. Pivot through Okta / Azure AD
Abuse SSO to jump from one app to another, hunting for cloud admin and VMware vCenter credentials.
5. Exfiltrate first, encrypt later
Sensitive data is copied out using common tools, so the operators can still extort you even if your backups are clean.
6. Deploy ransomware on hypervisors
Reported deployment of ALPHV/BlackCat against MGM's VMware ESXi servers. Every VM on the host goes down at once.
7. Demand payment, threaten leaks
Operators contact executives directly (often with harassment), demanding crypto payment to decrypt and to not publish data.
8. Move to the next victim
Members rotate through the loose online community known as "the Com." When one is arrested, the playbook continues with others.
None of these needed a technical vulnerability.
Every case above ran on a phone call, a vendor, or a help desk. Six defenses cover most of what Scattered Spider and crews like them actually do.
Train anyone who can reset a password
Anyone who handles password resets needs a verification script. Callers must answer specific identity questions before any reset happens.
Move off SMS-based MFA
SMS codes can be stolen via SIM swap. Use authenticator apps with number matching, or hardware keys (YubiKey) for accounts that matter.
Audit what staff posts on LinkedIn
Job titles, team names, internal jargon, badge photos. All give attackers what they need to sound like an insider on a phone call.
Ask vendors how they verify you
Caesars wasn't broken at Caesars. It was broken at an outsourced help desk. Ask every vendor how they handle reset requests.
Have a written incident plan
Who do you call at 2 a.m.? Which insurer, lawyer, bank? Print it. Tape it inside a desk drawer. Don't google answers mid-incident.
Back up what you can't survive losing
Customer records, accounting files, photos. Backups have to be offline, tested, and recent. Not just a cloud sync the attacker can encrypt.
Want me to take a look?
Email me and we will set up a free consultation. Tell me what you run and what you are worried about, and I will tell you whether there is anything worth doing.
yeriahz@sscsnv.comSources: US Department of Justice press releases, Bloomberg, CyberScoop, Las Vegas Review-Journal, News3LV, Clark County District Court filings, TRM Labs blockchain analysis, CDK Global public statements, Reuters, KrebsOnSecurity, MGM & Caesars SEC 8-K filings, Mandiant + Microsoft + Palo Alto Unit 42 threat-actor briefings. BlackSuit attribution for the CDK Global incident is based on widely reported industry analysis and blockchain tracing and has not been officially confirmed by CDK Global. Scattered Spider attribution for the direct Findlay breach is alleged and has not been officially confirmed by law enforcement as of this writing. Individuals named in arrest records and court filings are presumed innocent until proven guilty.