What Happened in the MGM Hack

In September 2023, MGM Resorts International suffered a cyber incident that disrupted hotel operations, slot machines and reservation systems for days. Reports estimate the cost of the breach at around US$100 million. The attackers did not exploit a software vulnerability or deploy zero‑day malware. Instead, they called the help desk.

Bloomberg reported at the time that the attack began with a social engineering breach of MGM’s IT help desk, citing a cybersecurity executive familiar with the investigation (Bloomberg, 2023). Weeks later, MGM’s chief executive, Bill Hornbuckle, told a gaming industry conference that the company’s technical call center was “the layer that got engineered” (Las Vegas Review-Journal, 2023). From there, the attackers moved through the network, deployed ransomware and stole data. The incident shows how social engineering at the help desk can get past sophisticated technical controls.

How Social Engineering Bypassed MFA

Multi‑factor authentication is designed to protect accounts when passwords are compromised. However, its effectiveness hinges on the secure issuance and management of the second factor. Help‑desk social engineering goes after weaknesses in this process:

  • Answering security questions – Attackers gather enough personal information to answer the knowledge‑based questions a help‑desk agent asks. Public data breaches and social‑media profiles provide names, addresses, birth dates and even pet names. With these details, attackers can convincingly impersonate legitimate users.
  • Requesting a new MFA device – Attackers claim the employee has changed phone numbers or lost a device, and an agent eager to help removes the existing MFA and enrolls a new one. The Hacker News explains that scammers often ask agents to send the MFA reset link to a new email or phone, enabling them to complete the process.
  • Circumventing push notifications – In some cases, attackers use MFA fatigue by sending repeated push prompts until the victim approves out of frustration. They may call the victim pretending to be IT support and instruct them to approve the login. A help‑desk MFA reset sidesteps this tactic entirely.
  • Using legitimate credentials – Once a new MFA device is enrolled, the attacker holds legitimate credentials, and the login looks normal to detection tools.

This attack underscores the reality that MFA is not a silver bullet. Without robust identity verification and process controls, determined attackers can social‑engineer their way past it.

Why Help Desks Are Vulnerable

Help desks exist to assist employees with access issues. Their goal is to resolve problems quickly and maintain productivity. Unfortunately, this mission makes them attractive targets. Several factors contribute to their vulnerability:

  • Human nature – Help‑desk agents are trained to be helpful and empathetic. Attackers exploit this by conveying urgency and building rapport. The Canadian Centre for Cyber Security notes that vishers use fraudulent phone numbers and voice alteration software to impersonate trusted individuals. Agents may feel pressured to resolve issues quickly and may bypass security steps.
  • Knowledge‑based authentication – Many help desks still rely on security questions, last four digits of Social Security numbers or other personal data for verification. In the age of massive data breaches, attackers can easily find this information.
  • Uniform processes – Large organizations often use the same procedure for all accounts. The Hacker News points out that this uniformity allows attackers to target high‑privilege accounts; the same script resets an administrator’s MFA and a receptionist’s.
  • Lack of identity proofing – Few organizations require government ID scans or biometric checks when someone calls in. Without strong identity proofing, it is difficult to distinguish a legitimate user from an impostor.
  • Insufficient training and policies – Help‑desk staff may not be trained to recognize social‑engineering tactics. Policies may not require multi‑party approval or call‑backs to official numbers.

Attackers understand these weaknesses. They invest time in research and rehearsal. A single successful call can grant them the keys to the kingdom.

How to Protect Against Similar Attacks

The MGM incident prompted many organizations to re‑evaluate their help‑desk procedures. To prevent similar breaches, consider the following measures:

  1. Implement secure identity proofing – Require callers to verify their identity using a secure, out‑of‑band process. Solutions like Trusona send the caller a verification link and check their government ID against the authority that issued it, with no app download and no pre‑registration.
  2. Use phishing‑resistant MFA and hardware tokens – Replace SMS codes with FIDO2 passkeys or security keys. Google found that after mandating hardware security keys, no employees were successfully phished. Even if attackers call the help desk, they cannot authenticate without the physical key.
  3. Script the help‑desk workflow – Provide agents with step‑by‑step scripts that enforce security policies. For high‑privilege accounts, require multi‑party approval or in‑person verification. Deny requests to send reset links to new contact information.
  4. Educate and empower employees – Train help‑desk personnel to recognize social‑engineering tactics. Encourage them to slow down, verify details and follow protocol. Educate all employees about vishing and MFA fatigue. Remind them never to approve unsolicited push notifications or share authentication codes.
  5. Monitor and audit – Log all password resets and MFA changes. Use analytics to detect anomalies, such as repeated resets or requests from unusual locations. Review logs regularly to ensure that policies are followed.
  6. Report and respond quickly – The FBI encourages prompt reporting of social‑engineering incidents. Early detection and response can prevent further compromise and minimize damage.
  7. Adopt a zero‑trust mindset – As Industrial Cyber notes, zero‑trust requires verifying both the subject and the device before starting a session. Extend this philosophy to the help desk: treat every request as untrusted until verified.

Conclusion

The MGM Resorts breach is a cautionary tale about the limits of traditional security controls. Social engineering at the help desk led to an estimated US$100 million in damages, and MGM’s own chief executive named the technical call center as the layer that got engineered. This incident underscores the need for strong help‑desk defenses. By implementing secure identity proofing, phishing‑resistant MFA, scripted workflows and robust training, organizations can prevent social‑engineering attacks from escalating into multimillion‑dollar disasters. Are you protected?

ATO Protect verifies the call that started MGM.