{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:21:22.539Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"MGM Resorts shut down for ten days after a help desk social engineering call","date":"2023-09-11","date_precision":"day","victim_org":"MGM Resorts International","sector":"Gaming & Casino","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI or voice cloning was reported; the reported method was a live human call using details gathered from public professional profiles.","outcomes":["Ransomware Deployment","Service Disruption","Data Breach","Extortion"],"loss_usd":110000000,"loss_note":"MGM reported roughly $100 million of negative impact to Las Vegas and regional operations' adjusted property earnings plus under $10 million of one-time costs; a $45 million class settlement covering this and an earlier breach was approved later.","records_affected":null,"threat_actor":"Scattered Spider, an affiliate of ALPHV/BlackCat","summary":"MGM Resorts disclosed a cybersecurity issue on 12 September 2023 that took hotel reservation systems, digital room keys, slot machines and its website offline across US properties for about ten days. In its Q3 2023 filing MGM reported roughly $100 million of negative impact to Las Vegas Strip adjusted property EBITDAR, plus under $10 million in one-time costs, and said personal data of customers who transacted before March 2019 was stolen, including names, contact details, dates of birth and driver's licence numbers, and Social Security and passport numbers for a subset. Scattered Spider, working with ALPHV/BlackCat, claimed responsibility.","how_it_worked":"MGM has never published the entry point, but the widely reported account, consistent with the CISA advisory and Okta's contemporaneous warning, is that the crew identified an MGM employee from a public professional profile, gathered enough personal and organisational detail to pass as them, and phoned the IT help desk to obtain a credential and MFA reset in a call reported to have lasted about ten minutes. With a legitimate identity re-issued to them, the actors escalated inside the identity provider and, after exfiltration, deployed ransomware against virtualisation infrastructure.","lessons":"High-privilege credential and MFA resets should never be grantable on a single inbound phone call; out-of-band verification with a known manager or video identity check would have cost the caller the whole operation.","confidence":"Reported","sources":[{"title":"Ransomware attack on MGM Resorts costs $110 Million","url":"https://securityaffairs.com/152077/cyber-crime/mgm-resorts-ransomware-attack.html","publisher":"Security Affairs"},{"title":"MGM Resorts confirms hackers stole customers' personal data during cyberattack","url":"https://techcrunch.com/2023/10/06/mgm-resorts-admits-hackers-stole-customers-personal-data-cyberattack/","publisher":"TechCrunch"},{"title":"Scattered Spider (AA23-320A)","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a","publisher":"CISA / FBI"},{"title":"A full timeline of the MGM Resorts cyber attack","url":"https://www.cshub.com/attacks/news/a-full-timeline-of-the-mgm-resorts-cyber-attack","publisher":"Cyber Security Hub"}],"entry_type":"incident","slug":"2023-mgm-resorts-shut-down-for-ten-days-after-a-help-desk-social-engineering","year":2023,"loss_kind":"business_impact","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-mgm-resorts-shut-down-for-ten-days-after-a-help-desk-social-engineering"}]}