MGM Resorts Cyberattack (Scattered Spider / ALPHV Vishing Ingress)
Key Facts
- Legal Status: ALLEGED in U.S. District Court for the District of Nevada.
- Primary Target Sector: Hospitality, Gaming, Entertainment.
- Documented Financial Loss: $100.0 million.
- 3 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
A 10-minute social engineering voice phishing (vishing) call to the Okta IT helpdesk impersonating an employee found on LinkedIn, convincing technicians to reset their MFA credentials.
Operational & Financial Fallout
Paralyzed MGM Resorts operations for 10 days, shutting down digital hotel room keys, casino slot machines, ATM cash-out terminals, and online reservation systems across the Las Vegas Strip. MGM incurred a $100 million negative operating earnings impact and $10 million in technology costs.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
A 10-minute social engineering voice phishing (vishing) call to the Okta IT helpdesk impersonating an employee found on LinkedIn, convincing technicians to reset their MFA credentials.
Adversary Kill Chain Flow
3 Documented PhasesScattered Spider operatives called the IT support desk impersonating a corporate employee, successfully convincing the helpdesk technician to enroll an attacker-controlled MFA device.
Attackers manipulated identity federation trusts, assigning themselves Global Administrator privileges in Microsoft Azure Active Directory and Super Admin roles in Okta.
When defenders initiated containment actions, the threat actors retaliated by deploying ALPHV/BlackCat ransomware across VMware ESXi virtual hypervisors, encrypting hundreds of virtual machines simultaneously.
Paralyzed MGM Resorts operations for 10 days, shutting down digital hotel room keys, casino slot machines, ATM cash-out terminals, and online reservation systems across the Las Vegas Strip. MGM incurred a $100 million negative operating earnings impact and $10 million in technology costs.
Procedural & Incident Timeline
MGM Resorts discovers unauthorized cybersecurity incident and proactively shuts down guest portals and gaming floors.
MGM Resorts files Form 8-K disclosure detailing $100 million operating income impact and $10 million in one-off technology expenses.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1566.004 | "Operatives conducted targeted voice phishing (vishing) calls to the internal IT helpdesk, impersonating an MGM employee identified on LinkedIn to successfully request a password reset and MFA credential registration." | CISA & FBI Joint Advisory AA23-320A | reviewed | |
| T1078 | Valid Accounts Defense Evasion | "After securing initial access, attackers elevated their privileges into Okta Identity Cloud and Microsoft Azure tenants, establishing super administrator roles to persist across the enterprise." | CISA Advisory AA23-320A, Page 4 | reviewed |
| T1486 | Data Encrypted for Impact Impact | "Upon encountering administrative containment attempts by defenders, the threat actors deployed ALPHV/BlackCat ransomware binaries across ESXi virtual machines, shutting down hotel check-in and gaming operations." | MGM SEC Form 8-K Filing | reviewed |