MGM Resorts International
On the evening of September 10, 2023 an operator placed a call to MGM's IT help desk. Within roughly ten minutes they had convinced help-desk staff to reset the password and MFA of an MGM employee they had identified on LinkedIn.
From that single account they pivoted through MGM's Okta identity platform into Microsoft 365 and Azure, located VMware vCenter administrator credentials, and deployed ALPHV/BlackCat ransomware against roughly 100 ESXi hypervisors. Encrypting hypervisors is a force multiplier: every virtual machine on the host goes dark at once. This is why slot machines, hotel digital keys, booking systems, restaurant POS, and the MGM Rewards app all went offline simultaneously.
The outage lasted more than 36 hours for core systems. Slot floors at the Bellagio, Aria, MGM Grand, Mandalay Bay, and other MGM properties went dark. Hotel guests waited in line while front-desk staff wrote room keys by hand. MGM's October 5, 2023 SEC 8-K filing disclosed approximately $100 million in operational impact, plus roughly $10 million in one-time remediation costs.
Customer data of approximately 10 million prior guests was reported stolen: names, dates of birth, contact info, and for a subset, driver's license and passport numbers. MGM publicly refused to pay the ransom.
The attack chain did not require a zero-day, an exploit, or any technical vulnerability in MGM's software. It required a phone, a LinkedIn account, and an IT help desk willing to reset a password for a confident caller. That is the entire playbook.
MGM Resorts International SEC Form 8-K (Oct 5, 2023); Mandiant + Okta incident briefings; KrebsOnSecurity coverage; Bloomberg; Reuters. Public statements from MGM and reporting on Scattered Spider tradecraft.
Same playbook, different victim.
Caesars
Compromised through a vendor's help desk. Loyalty-program data exfiltrated. Caesars reportedly paid ~$15M of a ~$30M ransom demand to keep operations running.
Findlay Direct
Henderson-headquartered dealership chain breached directly. 30+ dealerships across 5 states. Customer + employee PII exposed. Class-action lawsuits in Clark County.
Findlay via CDK
Two weeks after the direct breach, Findlay's software vendor CDK Global was ransomed. ~15,000 dealers nationwide reverted to pen and paper for ~2 weeks.
Want to know if your business survives this playbook?
Free 15-minute call. We'll walk through your help-desk process, MFA setup, and three things you can fix this week.
Book a free consultation