Four attacks. One playbook.
Real cyberattacks on Las Vegas–area businesses, broken down step by step. Pick a case to see the timeline, the technique, and what a small business can learn from it.
Pick a case.
MGM Resorts International
A 10-minute phone call to the IT help desk shut down slot machines, hotel keys, and booking systems for more than 36 hours. ~$100M in operational losses.
Caesars Entertainment
Compromised through a vendor's help desk. Loyalty-program data exfiltrated. Caesars reportedly paid ~$15M of a ~$30M ransom demand to keep operations running.
Findlay Automotive Group: Direct Breach
Henderson-headquartered dealership chain breached directly. 30+ dealerships across 5 states. Customer + employee PII exposed. Class-action lawsuits in Clark County.
Findlay Automotive via CDK Global: Supply Chain
Two weeks after the direct breach, Findlay's software vendor CDK Global was ransomed. ~15,000 dealers nationwide reverted to pen and paper for ~2 weeks.
Scattered Spider, a loose collective of young, English-speaking operators.
Scattered Spider is not a traditional ransomware crew. It is a fluid set of operators (many in their late teens and early twenties) who meet through gaming platforms, Discord, and Telegram channels that researchers loosely call “the Com.”
Their edge isn't a novel exploit. It is fluent English, a calm phone voice, and the patience to research one employee until they can convince an IT help desk they're that employee. They are responsible for three of the four cases above (MGM, Caesars, and the alleged direct Findlay breach).
- UNC3944 (Mandiant)
- Octo Tempest (Microsoft)
- 0ktapus
- Scatter Swine
- Muddled Libra (Unit 42)
- Star Fraud
Distributed across the US and UK. Several members have been publicly identified.
Conspiracy to commit wire fraud, identity theft, and aggravated identity theft.
Arrested at Palma airport; US filed wire fraud and aggravated identity theft charges.
DOJ unsealed charges against Ahmed Elbadawy, Noah Urban, Evans Osiebo, Joel Evans, and Tyler Buchanan for a wire-fraud conspiracy.
Sources: DOJ press releases, Reuters, Bloomberg, KrebsOnSecurity. Charges do not equal conviction; individuals named are not assumed guilty.
The eight-step playbook. No zero-day required.
1. Reconnaissance on LinkedIn
Identify an IT or help-desk staff member at the target: name, role, manager, badge style, internal jargon.
2. Vish the help desk
Call IT pretending to be the employee. Calm voice, correct context, ask for a password and MFA reset.
3. Reset MFA, log in
Help desk resets MFA. Operator enrolls their own device. Now they log in as the real employee.
4. Pivot through Okta / Azure AD
Abuse SSO to jump from one app to another, hunting for cloud admin and VMware vCenter credentials.
5. Exfiltrate first, encrypt later
Sensitive data is copied out using common tools so it can be used as extortion leverage even if backups exist.
6. Deploy ransomware on hypervisors
Reported deployment of ALPHV/BlackCat against MGM's VMware ESXi servers. Every VM on the host goes down at once.
7. Demand payment, threaten leaks
Operators contact executives directly (often with harassment), demanding crypto payment to decrypt and to not publish data.
8. Move to the next victim
Members rotate through the loose online community known as "the Com." When one is arrested, the playbook continues with others.
A ten-minute phone call broke a $30 billion company.
You are easier than MGM was. Six practical defenses cover almost everything Scattered Spider (and most other crews) use.
Train anyone who can reset a password
Anyone who handles password resets needs a verification script. Callers must answer specific identity questions before any reset happens.
Move off SMS-based MFA
SMS codes can be stolen via SIM swap. Use authenticator apps with number matching, or hardware keys (YubiKey) for accounts that matter.
Audit what staff posts on LinkedIn
Job titles, team names, internal jargon, badge photos. All give attackers what they need to sound like an insider on a phone call.
Ask vendors how they verify you
Caesars wasn't broken at Caesars. It was broken at an outsourced help desk. Ask every vendor how they handle reset requests.
Have a written incident plan
Who do you call at 2 a.m.? Which insurer, lawyer, bank? Print it. Tape it inside a desk drawer. Don't google answers mid-incident.
Back up what you can't survive losing
Customer records, accounting files, photos. Backups have to be offline, tested, and recent. Not just a cloud sync the attacker can encrypt.
Want to know if your business survives this playbook?
Free 15-minute call. We'll walk through your help-desk process, MFA setup, and three things you can fix this week.
Book a free consultationSources: US Department of Justice press releases, Bloomberg, CyberScoop, Las Vegas Review-Journal, News3LV, Clark County District Court filings, TRM Labs blockchain analysis, CDK Global public statements, Reuters, KrebsOnSecurity, MGM & Caesars SEC 8-K filings, Mandiant + Microsoft + Palo Alto Unit 42 threat-actor briefings. BlackSuit attribution for the CDK Global incident is based on widely reported industry analysis and blockchain tracing and has not been officially confirmed by CDK Global. Scattered Spider attribution for the direct Findlay breach is alleged and has not been officially confirmed by law enforcement as of this writing. Individuals named in arrest records and court filings are presumed innocent until proven guilty.