{
  "id": "case-mgm-scattered-spider",
  "slug": "mgm-resorts-scattered-spider",
  "title": "MGM Resorts Cyberattack (Scattered Spider / ALPHV Vishing Ingress)",
  "summary": "Sophisticated social engineering and ransomware attack carried out by cybercrime collective Scattered Spider partnering with ALPHV/BlackCat, utilizing a 10-minute phone call to the Okta IT helpdesk to bypass MFA, hijack administrative privileges, and paralyze hotel reservations, digital keys, and casino slot machines.",
  "case_number": "2:23-cv-01584",
  "court": "U.S. District Court for the District of Nevada",
  "district": "D. Nev.",
  "country": "United States",
  "opened_at": "2023-10-05",
  "status": "alleged",
  "victim_sector": "Hospitality, Gaming, Entertainment",
  "victim_country": "United States",
  "loss_amount_usd": 100000000,
  "loss_amount_note": "MGM Resorts disclosed a negative adjusted EBITDAR impact of roughly $100 million in its SEC Form 8-K filing.",
  "first_seen_at": "2023-09-08T00:00:00Z",
  "last_updated_at": "2026-09-18T10:00:00Z",
  "actor_slug": "scattered-spider",
  "defendant_slugs": [],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1566.004",
      "evidence_excerpt": "Operatives conducted targeted voice phishing (vishing) calls to the internal IT helpdesk, impersonating an MGM employee identified on LinkedIn to successfully request a password reset and MFA credential registration.",
      "evidence_locator": "CISA & FBI Joint Advisory AA23-320A",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA23-320A: Scattered Spider",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a"
    },
    {
      "technique_id": "T1078",
      "evidence_excerpt": "After securing initial access, attackers elevated their privileges into Okta Identity Cloud and Microsoft Azure tenants, establishing super administrator roles to persist across the enterprise.",
      "evidence_locator": "CISA Advisory AA23-320A, Page 4",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA23-320A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1486",
      "evidence_excerpt": "Upon encountering administrative containment attempts by defenders, the threat actors deployed ALPHV/BlackCat ransomware binaries across ESXi virtual machines, shutting down hotel check-in and gaming operations.",
      "evidence_locator": "MGM SEC Form 8-K Filing",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "SEC Form 8-K Disclosure: MGM Resorts",
      "source_url": "https://www.sec.gov",
      "technique_name": "Data Encrypted for Impact",
      "tactic": "Impact"
    }
  ],
  "events": [
    {
      "event_type": "incident",
      "event_date": "2023-09-10",
      "description": "MGM Resorts discovers unauthorized cybersecurity incident and proactively shuts down guest portals and gaming floors."
    },
    {
      "event_type": "filing",
      "event_date": "2023-10-12",
      "description": "MGM Resorts files Form 8-K disclosure detailing $100 million operating income impact and $10 million in one-off technology expenses."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "A 10-minute social engineering voice phishing (vishing) call to the Okta IT helpdesk impersonating an employee found on LinkedIn, convincing technicians to reset their MFA credentials.",
    "blast_radius": "Paralyzed MGM Resorts operations for 10 days, shutting down digital hotel room keys, casino slot machines, ATM cash-out terminals, and online reservation systems across the Las Vegas Strip. MGM incurred a $100 million negative operating earnings impact and $10 million in technology costs.",
    "kill_chain": [
      {
        "phase": "Social Engineering Ingress",
        "title": "Helpdesk Vishing and MFA Registration",
        "description": "Scattered Spider operatives called the IT support desk impersonating a corporate employee, successfully convincing the helpdesk technician to enroll an attacker-controlled MFA device.",
        "technical_artifacts": [
          "Voice phishing (vishing)",
          "LinkedIn employee OSINT"
        ],
        "mitre_technique_id": "T1566.004"
      },
      {
        "phase": "Identity Cloud Takeover",
        "title": "Okta Super Admin and Azure AD Elevation",
        "description": "Attackers manipulated identity federation trusts, assigning themselves Global Administrator privileges in Microsoft Azure Active Directory and Super Admin roles in Okta.",
        "technical_artifacts": [
          "Okta Identity Cloud tenant takeover",
          "Azure AD Global Admin"
        ],
        "mitre_technique_id": "T1078"
      },
      {
        "phase": "Virtualization Encryption",
        "title": "ALPHV/BlackCat ESXi Hypervisor Detonation",
        "description": "When defenders initiated containment actions, the threat actors retaliated by deploying ALPHV/BlackCat ransomware across VMware ESXi virtual hypervisors, encrypting hundreds of virtual machines simultaneously.",
        "technical_artifacts": [
          "ALPHV Linux/ESXi ransomware",
          "VMware vSphere console abuse"
        ],
        "mitre_technique_id": "T1486"
      }
    ],
    "defensive_takeaways": [
      "Implement mandatory out-of-band video or manager verification for all helpdesk MFA and password resets.",
      "Transition to FIDO2 phishing-resistant hardware security keys that cannot be phished over the phone.",
      "Restrict ESXi hypervisor management interfaces to isolated out-of-band management subnets.",
      "Enable conditional access rules that detect anomalous location and device changes on administrative accounts."
    ]
  }
}