Case #001: The $100 Million Phone Call

Target: MGM Resorts International

Date: September 2023

Threat Actor: Scattered Spider / ALPHV

Attack Vector: Voice Phishing (Vishing) & MFA Bypass

Impact: $100m+ operational loss

The Crack

Lack of identity verification at the IT Servicedesk.

MFA is designed to be an ‘unpickable lock’ but the attackers bypassed it by calling support and asking for them to unlock the door for them

The Execution

  • Reconnaisance: The attackers picked an active employee on LinkedIn, noting their full name, job title and department. Using public data brokers they were able to find the employees phone number and date of birth
  • Help Desk Call: Posing as the employee they called MGM’s internal IT servicedesk claiming to be locked out. Using the harvested details, they were able to pass basic identity checks
  • MFA Hijack: The servicedesk reset the account credentials and bound the employee’s MFA token directly to the attacker’s personal device
  • Domain Takeover: With legitimate credentials, the attackers moved laterally through the networks, gained super-admin with MGM’s Okta identity tenant and deployed ransomware across internal systems

The Blast Radius

  • 10 days of Downtime: Digital keycards, casino slot machiens, hotel reservation engines and payments systems all offline forcing the staff to revert to pen and paper
  • Data Stolen: Drivers licenses, passport details, social security numbers of past guests were exfiltrated
  • Financial Loss: Over $100m in direct operational losses alongside tens of millions of remediation costs
  • Reputational Loss: The event hit all the major news channels across the US and many of the popular online publications globally

The Hardening Plan

  • Ditch Knowledge-Based Verification: Information availabile on social media or breaches (DoB, phone numbers, employee IDs, etc) should never be used to verify identity during account resets
  • Enforce Out-of-Band Approvals: Requests for credential or MFA resets must require secondary confirmation, for example – a managers visual sign-off or a push-notification to an already trusted device
  • Tiered Identity Guardrails: Servicedesk staff shouldn’t have the authority to register new primary authentication methods for high-privilege users without security alerts as a minimum.
Scroll to Top