Source: Wikimedia Commons 

Somewhere in Las Vegas, a phone rang.

On the other end was an IT help desk employee, mid-shift, doing exactly what the job asked of them — solving a locked-out colleague's problem, quickly and kindly. There was no dramatic tell. No warning banner, no suspicious link, no virus signature flashing red. Just a voice that sounded right, at exactly the right moment, asking for something help desks grant dozens of times a day: a password reset.

Ten minutes later, the call ended. Whoever was on the line now held credentials belonging to someone else.

By the next morning, slot machines across one of the world's largest casino and hotel companies were dead. Guests swiped room key cards and got nothing but a red light. Front-desk staff, locked out of their own booking system, started writing names on paper by hand. Some properties reportedly asked guests to pay in cash.

This is MGM Resorts, September 2023. And the thing that brought a global hospitality giant to a standstill wasn't a hacker in a hoodie or a piece of malicious code. It was a phone call. This is a story about that call — and about how trust, not technology, has become the easiest door into some of the most heavily defended companies on earth.

Who was in the room

MGM Resorts International runs more than thirty properties, including the Bellagio, MGM Grand, Mandalay Bay, and Aria, and employs roughly 75,000 people. On paper, this should be one of the hardest companies in America to break into. Casinos live and die by security — cameras on every angle, biometric access, surveillance rooms watching the watchers.

None of that mattered on September 11.

The attackers belonged to a group researchers call Scattered Spider — also tracked as UNC3944 and Octo Tempest — a loose, largely English-speaking collective known less for writing code and more for reading people. Their method, confirmed across multiple cybersecurity investigations and MGM's own regulatory filings, didn't require a single exploit. They searched LinkedIn for a real MGM employee, gathered enough personal details to sound convincing, and called the company's help desk pretending to be that person, locked out of their own account.

The employee who answered wasn't careless. They weren't undertrained in any way that would show up on a performance review. They were doing the job exactly as designed — helping someone who sounded like they belonged. There's no public record of what happened to that employee afterward. But it's not hard to imagine those ten minutes replaying in their head once the outages made the news.

Reconstructing the ten minutes

Here is what security researchers, including analysts at Palo Alto Networks' Unit 42, pieced together.

First, reconnaissance. Scattered Spider identified a high-value MGM employee, someone with elevated system privileges, through nothing more exotic than a LinkedIn profile revealing a job title and a team structure. Then, the call: impersonate that employee and ask the help desk to reset their multi-factor authentication.

This should have been the hard part, and it wasn't. Help desks reset MFA constantly — for people who lost a phone, switched devices, forgot a password on a Monday morning. MGM used Okta for identity management, and like most enterprise systems, Okta grants help desk staff exactly this power by default. It is a convenience that works fine until someone dishonest is on the other end of the line.

The moment the reset went through, the attackers now controlled a privileged account with far-reaching access. What they did next is the part that should unsettle anyone who thinks a stolen password is a contained problem. Using a legitimate Okta feature called "inbound federation," they quietly built themselves a second, invisible identity provider inside MGM's own system — a spare key to a lock the homeowner didn't know existed. From there, they moved into Microsoft Azure, then into the wider infrastructure.

MGM's security team caught the intrusion around September 10 and did the only thing left to do: shut systems down to stop the bleeding. That shutdown is what guests actually experienced — the dead slot machines, the failed key cards, the paper check-ins. Behind the scenes, a ransomware group known as ALPHV, working alongside Scattered Spider, had already begun encrypting several hundred of MGM's servers, according to one cybersecurity assessment of the breach. MGM refused to pay. The company later disclosed an estimated $100 million hit to its third-quarter earnings from lost revenue, legal costs, and recovery.

Ten minutes on the phone. Ten days of chaos. One hundred million dollars.

The attack, explained without the jargon.

Strip away the vocabulary, and the mechanics are almost embarrassingly simple.

Every company keeps a front door open for employees who forget their passwords — a help desk that can reset an account so someone can get back to work. Multi-factor authentication is the extra lock on that door: even if your password leaks, it shouldn't be enough on its own to get anyone in. But a reset of that very lock, requested convincingly enough, hands an attacker the same access as the real employee. No malware. No hacking tool. No code at all.

"Inbound federation" sounds technical. It functions like adding a hidden second key to a lock, one the homeowner never notices is there. Once it exists, the attacker doesn't need to keep breaking in. They can simply walk through any time they like.

Everything — the ten-minute call, the nine-figure bill, ten days of chaos across thirty properties — traced back to one moment: convincing a human being, in real time, that a story was true.

Why the technology didn't save anyone

MGM had firewalls, encryption, and round-the-clock monitoring, run by a security team that, by any technical measure, was doing its job. The firewalls, the encryption, the monitoring — none of it got a chance to matter, because the attack was never aimed at any of it. It was aimed at a person, and it pulled on five psychological levers that show up, again and again, in nearly every social engineering case on record.

Authority. The caller sounded like someone with a legitimate claim on the system — an employee, not an intruder. Help desks are built to serve authorised users, not interrogate them.

Urgency. Being locked out of your own accounts at work is stressful, immediate, and easy to weaponise. Manufactured urgency shrinks the window in which anyone stops to double-check a story.

Familiarity. A detail lifted from a real employee's LinkedIn profile — their team, their title, their manager's name — makes an impersonation feel instantly credible. It erases the friction that might otherwise trigger suspicion.

Cognitive overload. Help desk staff field dozens of near-identical requests a day. Verification steps that exist on paper quietly compress under real call volume and real time pressure.

Trust. Underneath all four of the above sits the same single target: the human instinct to believe someone who sounds like they belong.

It took research, nerve, and an understanding of how help desks actually behave under pressure — not how the security policy says they should behave.

A pattern, not an anomaly

If this happened once, it would be a cautionary tale. It happened three times in three years, and two of those times within days of each other.

Within days of the MGM breach, Caesars Entertainment disclosed a strikingly similar incident. According to Caesars' own SEC filing and reporting from the Wall Street Journal, attackers used social engineering against an outsourced IT support vendor in mid-August 2023, gaining access to Caesars' network and stealing a loyalty program database holding Social Security and driver's license numbers for a large share of its 65 million members. Unlike MGM, Caesars reportedly paid around $15 million of a $30 million ransom demand to keep the data from going public. Security researchers linked both breaches to the same threat actors, using nearly identical methods, within the same month.

Rewind three years, and the pattern already existed. In July 2020, Twitter suffered its own lesson in how little malware has to do with a modern breach. Attackers ran what the company called a "phone spear phishing attack" against a small group of employees, tricking them into handing over credentials to internal tools. According to Twitter's own account, those first stolen credentials gave the attackers enough insight into internal systems to target additional employees who held access to account support tools — eventually compromising roughly 130 high-profile accounts, including public figures and major companies, to run a cryptocurrency scam. Again: no malicious code. A convincing phone call and an employee trying to be helpful.

Three companies. Three years of the same script, and the same weakness, arriving at the same ending.

What experts say organisations still get wrong

Researchers who study these cases keep circling back to one blind spot: companies pour money into technical defences while treating human verification as an afterthought. Help desks are handed broad reset privileges by default, in the name of convenience, and the setting is rarely revisited once it's live. Security training tends to focus on suspicious emails and phishing links — the threat everyone has been warned about — while phone-based impersonation, often harder to catch in the moment, gets a fraction of the attention despite sitting behind some of the decade's most damaging breaches.

There's a blind spot on the individual side, too. The professional detail people post to LinkedIn — job titles, team structures, manager names — is exactly the raw material an attacker needs to sound real. Almost no one updating their profile stops to consider that career visibility could double as a company's entry point.

The uncomfortable part researchers keep landing on is this: the more helpful and responsive a company trains its staff to be, the more exploitable that helpfulness becomes, unless verification is built in as a rule rather than offered as a courtesy.

What can actually be done?

For individuals: treat any unexpected request to reset a password or MFA device — even one that sounds like it's coming from your own company — as something to verify through a separate, known channel before acting. Think twice about how much operational detail sits on a public profile.

For businesses: require callback verification or in-person confirmation before any privileged account reset, especially MFA. Audit which staff, including outsourced help desk vendors, can alter authentication settings, and cut that list down to the minimum necessary.

For students entering the workforce, cybersecurity literacy isn't only about spotting a fake email anymore. Learning to recognise manufactured urgency and unearned authority in a phone call is a skill that outlasts any single job.

For families: the same levers — a trusted voice, urgency, fear — are the exact ones used in scams against elderly relatives and children, not just corporations. A single honest conversation at home about how these calls work is the same instinct that could have stopped a hundred-million-dollar breach.

What's left after the malware isn't there

There is something almost quaint about a story where the villain doesn't need a laptop full of exploits — just a phone, a LinkedIn profile, and ten minutes of nerve. It would be easier if breaches like this required elite skill. They don't. They require someone willing to ask and someone else willing to help.

That is the uncomfortable centre of this story. No security policy can strip out the instinct to trust a stranger's voice without breaking the thing it exists to protect. The harder, less satisfying work is building a system that can still be kind without being gullible.

Ten days after that phone call, one of the world's largest casino operators was still recovering — its systems down, its guests checking in by hand, its costs climbing toward nine figures.

No hacker broke into MGM Resorts. No malware touched its servers. Someone sounded convincing, and someone else wanted to help. That's the whole story — and it's exactly why it should worry you.

.    .    .