{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:20:10.736Z","total":7,"returned":7,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"MGM Resorts shut down for ten days after a help desk social engineering call","date":"2023-09-11","date_precision":"day","victim_org":"MGM Resorts International","sector":"Gaming & Casino","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI or voice cloning was reported; the reported method was a live human call using details gathered from public professional profiles.","outcomes":["Ransomware Deployment","Service Disruption","Data Breach","Extortion"],"loss_usd":110000000,"loss_note":"MGM reported roughly $100 million of negative impact to Las Vegas and regional operations' adjusted property earnings plus under $10 million of one-time costs; a $45 million class settlement covering this and an earlier breach was approved later.","records_affected":null,"threat_actor":"Scattered Spider, an affiliate of ALPHV/BlackCat","summary":"MGM Resorts disclosed a cybersecurity issue on 12 September 2023 that took hotel reservation systems, digital room keys, slot machines and its website offline across US properties for about ten days. In its Q3 2023 filing MGM reported roughly $100 million of negative impact to Las Vegas Strip adjusted property EBITDAR, plus under $10 million in one-time costs, and said personal data of customers who transacted before March 2019 was stolen, including names, contact details, dates of birth and driver's licence numbers, and Social Security and passport numbers for a subset. Scattered Spider, working with ALPHV/BlackCat, claimed responsibility.","how_it_worked":"MGM has never published the entry point, but the widely reported account, consistent with the CISA advisory and Okta's contemporaneous warning, is that the crew identified an MGM employee from a public professional profile, gathered enough personal and organisational detail to pass as them, and phoned the IT help desk to obtain a credential and MFA reset in a call reported to have lasted about ten minutes. With a legitimate identity re-issued to them, the actors escalated inside the identity provider and, after exfiltration, deployed ransomware against virtualisation infrastructure.","lessons":"High-privilege credential and MFA resets should never be grantable on a single inbound phone call; out-of-band verification with a known manager or video identity check would have cost the caller the whole operation.","confidence":"Reported","sources":[{"title":"Ransomware attack on MGM Resorts costs $110 Million","url":"https://securityaffairs.com/152077/cyber-crime/mgm-resorts-ransomware-attack.html","publisher":"Security Affairs"},{"title":"MGM Resorts confirms hackers stole customers' personal data during cyberattack","url":"https://techcrunch.com/2023/10/06/mgm-resorts-admits-hackers-stole-customers-personal-data-cyberattack/","publisher":"TechCrunch"},{"title":"Scattered Spider (AA23-320A)","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a","publisher":"CISA / FBI"},{"title":"A full timeline of the MGM Resorts cyber attack","url":"https://www.cshub.com/attacks/news/a-full-timeline-of-the-mgm-resorts-cyber-attack","publisher":"Cyber Security Hub"}],"entry_type":"incident","slug":"2023-mgm-resorts-shut-down-for-ten-days-after-a-help-desk-social-engineering","year":2023,"loss_kind":"business_impact","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-mgm-resorts-shut-down-for-ten-days-after-a-help-desk-social-engineering"},{"title":"Caesars pays reported $15M ransom after outsourced IT vendor is socially engineered","date":"2023-08-18","date_precision":"day","victim_org":"Caesars Entertainment","sector":"Gaming & Casino","country":"United States","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Help Desk Impersonation","Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Extortion","Wire Fraud / Financial Loss"],"loss_usd":15000000,"loss_note":"Reported ransom payment of roughly $15 million, about half of an initial $30 million demand, per Bloomberg and other reporting; Caesars confirmed in its 8-K that it took steps to ensure the stolen data was deleted but did not confirm the amount.","records_affected":null,"threat_actor":"Scattered Spider, reportedly working with ALPHV/BlackCat","summary":"Caesars told the SEC that a social engineering attack on an outsourced IT support vendor gave attackers unauthorised access on 18 August 2023, with data taken on 23 August and the incident discovered on 7 September. The loyalty programme database was stolen, including Social Security and driver's licence numbers; roughly 41,397 Maine residents were among those notified. Caesars reportedly paid millions to prevent publication. Payment card and bank account data were not accessed.","how_it_worked":"Caesars outsourced IT support, so the people who could reset credentials sat at a vendor, outside Caesars' own security culture and monitoring. The actors called that vendor's support staff impersonating Caesars employees, used voice-phishing techniques to get MFA enrolments changed, and inherited the identity of a real user. From there the path to the loyalty database was ordinary authorised access rather than exploitation. The extortion followed the same double-track playbook the group used against MGM the same month: steal first, threaten publication, negotiate.","lessons":"Extending help-desk identity-proofing standards, monitoring and MFA-reset approvals contractually into outsourced IT support is the control gap this incident exposed.","confidence":"Confirmed","sources":[{"title":"Caesars Entertainment says social-engineering attack behind August breach","url":"https://www.cybersecuritydive.com/news/caesars-social-engineering-breach/695995/","publisher":"Cybersecurity Dive"},{"title":"Scattered Spider (AA23-320A)","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a","publisher":"CISA / FBI"}],"entry_type":"incident","slug":"2023-caesars-pays-reported-15m-ransom-after-outsourced-it-vendor-is-socially","year":2023,"loss_kind":"ransom_paid","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-caesars-pays-reported-15m-ransom-after-outsourced-it-vendor-is-socially"},{"title":"Riot Games loses League of Legends source code to a social engineering attack","date":"2023-01","date_precision":"month","victim_org":"Riot Games","sector":"Gaming & Casino","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Extortion","Service Disruption"],"loss_usd":null,"loss_note":"Riot refused the $10 million ransom demand and did not publish remediation costs.","records_affected":null,"threat_actor":null,"summary":"Riot Games disclosed in January 2023 that attackers used social engineering to compromise its development environment and steal source code for League of Legends and Teamfight Tactics along with a legacy anti-cheat platform. The company received a ransom email demanding $10 million and publicly refused to pay. Riot said no player data or personal information was compromised, but the intrusion disrupted its build pipeline and delayed game patches.","how_it_worked":"Riot attributed the intrusion to social engineering rather than a software vulnerability and said an employee's access was the entry point, without publishing the script used. The attackers' goal shaped the tradecraft: rather than encrypting systems they moved quietly into the build and source environment, took the anti-cheat and game code that has resale value in the cheat-development market, and only surfaced afterwards with an emailed extortion demand. Riot's refusal to pay, and its public commitment to publish a post-incident report, limited the leverage the stolen code created.","lessons":"Source and build environments should require phishing-resistant MFA and device trust separately from general corporate SSO, so one socially engineered employee cannot reach them.","confidence":"Confirmed","sources":[{"title":"Riot Games receives 'ransom email' for stolen source code following social engineering attack","url":"https://therecord.media/riot-games-receives-ransom-email-for-stolen-source-code-following-social-engineering-attack","publisher":"The Record"},{"title":"Riot Games receives ransom demand from hackers, refuses to pay","url":"https://www.bleepingcomputer.com/news/security/riot-games-receives-ransom-demand-from-hackers-refuses-to-pay/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2023-riot-games-loses-league-of-legends-source-code-to-a-social-engineering-a","year":2023,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-riot-games-loses-league-of-legends-source-code-to-a-social-engineering-a"},{"title":"Activision breached after an HR employee falls for an SMS phishing message","date":"2022-12-04","date_precision":"day","victim_org":"Activision Blizzard","sector":"Gaming & Casino","country":"United States","primary_vector":"Smishing (SMS)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"No financial loss disclosed.","records_affected":19444,"threat_actor":null,"summary":"Activision confirmed in February 2023 that it had suffered a breach on 4 December 2022 after an employee in the human resources department responded to an SMS phishing message. Researchers who surfaced the incident said the attacker gained access to internal Slack, an employee data set and Activision's content release calendar, including planned Call of Duty content. Activision said it had addressed the incident promptly and that sensitive employee data was not exfiltrated in bulk.","how_it_worked":"The attacker sent text messages to an HR employee that led to credential capture, then used the account to move into internal collaboration systems. Once inside Slack, the intruder posted messages attempting to lure additional employees into clicking further links, using the credibility of an internal account to widen the compromise. They also accessed a spreadsheet of employee information including names, email addresses, phone numbers, salaries and office locations, and the marketing content calendar. Screenshots of the internal Slack activity and the stolen data were later published by researchers and on a hacking forum.","lessons":"Phishing-resistant MFA on corporate identity, plus alerting on internal chat messages that contain newly-registered external links, limits both the initial takeover and the internal spread.","confidence":"Reported","sources":[{"title":"Activision confirms data breach exposing employee and game info","url":"https://www.bleepingcomputer.com/news/security/activision-confirms-data-breach-exposing-employee-and-game-info/","publisher":"BleepingComputer"},{"title":"Hackers steal Activision games and employee data","url":"https://techcrunch.com/2023/02/21/hackers-allegedly-steal-activision-games-and-employee-data/","publisher":"TechCrunch"},{"title":"Activision Data Breach Contains Employee Details, Call of Duty's Future, and More","url":"https://insider-gaming.com/activision-data-breach/","publisher":"Insider Gaming"},{"title":"Threat actors leak Activision employee data on hacking forum","url":"https://securityaffairs.com/142779/data-breach/activision-data-leak.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2022-activision-breached-after-an-hr-employee-falls-for-an-sms-phishing-messa","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-activision-breached-after-an-hr-employee-falls-for-an-sms-phishing-messa"},{"title":"Rockstar Games internal Slack breached and GTA 6 footage leaked","date":"2022-09-18","date_precision":"day","victim_org":"Rockstar Games","sector":"Gaming & Casino","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_note":"Rockstar and parent Take-Two did not quantify losses publicly.","records_affected":null,"threat_actor":"Arion Kurtaj, linked to Lapsus$ (same actor as the Uber intrusion)","summary":"An actor using the handle teapotuberhacker, the same persona behind the Uber intrusion days earlier, posted roughly 90 in-development Grand Theft Auto VI videos and claimed to hold GTA V and GTA VI source code, saying they had reached Rockstar's internal Slack and Confluence. Rockstar confirmed a network intrusion and unauthorised access to early development footage. A UK teenager, Arion Kurtaj, was later convicted and in December 2023 given an indefinite hospital order.","how_it_worked":"The actor did not publish a technical exploit chain, and Rockstar has never described the entry point, so the mechanics are attacker-claimed and inferred from the same operator's behaviour at Uber days earlier: harvesting employee credentials and then talking a human into approving access, followed by collection from collaboration platforms rather than code repositories. Once inside Slack and Confluence the value was not code execution but corporate memory, build videos, design documents and chat, which the actor packaged directly into an extortion attempt and a public leak.","lessons":"Collaboration platforms hold the crown jewels for a media company and deserve the same phishing-resistant MFA, device trust and data-egress monitoring as source control.","confidence":"Alleged","sources":[{"title":"Alleged Grand Theft Auto 6 (GTA6) gameplay videos and source code leaked online","url":"https://securityaffairs.com/135923/data-breach/gta6-gameplay-videos-source-code-leak.html","publisher":"Security Affairs"},{"title":"London Police arrested a teen suspected to be behind Uber, Rockstar Games breaches","url":"https://securityaffairs.com/136146/cyber-crime/uber-rockstar-games-hacker-arrest.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2022-rockstar-games-internal-slack-breached-and-gta-6-footage-leaked","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-rockstar-games-internal-slack-breached-and-gta-6-footage-leaked"},{"title":"Electronic Arts source code stolen via Slack cookie and IT help desk impersonation","date":"2021-06","date_precision":"month","victim_org":"Electronic Arts","sector":"Gaming & Casino","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_note":"No confirmed payment or loss figure; the stolen data was advertised for sale on underground forums.","records_affected":null,"threat_actor":"Unnamed criminal group that spoke to Motherboard/Vice","summary":"In June 2021 attackers stole roughly 780GB of data from Electronic Arts, including source code for FIFA 21 and the Frostbite game engine. The intruders told Motherboard they bought stolen authentication cookies for about $10, used them to enter EA's Slack workspace, then messaged EA IT support claiming to have lost their phone at a party and asking for a new multifactor token. The request was granted twice, giving them corporate network access.","how_it_worked":"The chain began with a cookie sold on a criminal marketplace that carried a live Slack session for an EA employee. Inside Slack the attackers had the informal context, names and internal jargon needed to sound like staff. They then approached IT support in chat, claiming a lost phone, and persuaded the agent to issue a replacement MFA token without independent identity proofing. With working corporate credentials and MFA they reached EA's internal developer compilation service, created a virtual machine to gain broader network visibility, and downloaded game source code and internal tooling. EA said no player data was accessed.","lessons":"Help desk MFA resets need identity proofing that does not depend on the requester's own chat account, such as manager verification or a video check against an HR photo record.","confidence":"Reported","sources":[{"title":"How Hackers Used Slack to Break into EA Games","url":"https://www.vice.com/en/article/how-ea-games-was-hacked-slack/","publisher":"Vice / Motherboard"},{"title":"Hackers reportedly used EA Games' Slack to breach network, access source code","url":"https://cyberscoop.com/ea-games-fifa-hack-hackers-slack/","publisher":"CyberScoop"},{"title":"Details Emerge on How Gaming Giant EA Was Hacked","url":"https://www.darkreading.com/cyberattacks-data-breaches/report-details-how-gaming-giant-ea-was-hacked","publisher":"Dark Reading"}],"entry_type":"incident","slug":"2021-electronic-arts-source-code-stolen-via-slack-cookie-and-it-help-desk-imp","year":2021,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2021-electronic-arts-source-code-stolen-via-slack-cookie-and-it-help-desk-imp"},{"title":"Hacker bribed a Roblox support contractor to access user data and reset accounts","date":"2020-05","date_precision":"month","victim_org":"Roblox Corporation","sector":"Gaming & Casino","country":"United States","primary_vector":"Insider Recruitment","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Insider Access","Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"No dollar loss was published. The hacker changed passwords on two accounts and took in-game items from those users.","records_affected":null,"threat_actor":"Unnamed individual who had previously sought a Roblox bug bounty","summary":"A hacker bribed a Roblox customer support representative, listed publicly as an in-game support contractor, to obtain access to the company's customer support panel. The panel exposed personal data on Roblox's user base and allowed password resets, removal of two-factor authentication, account bans and data changes. Roblox said it acted immediately, notified the small number of affected customers, and reported the hacker to HackerOne.","how_it_worked":"The attacker skipped Roblox's perimeter entirely and bought a person instead. He identified a support contractor via LinkedIn and paid them for access to the internal customer support console, which was designed to let agents administer any account. With that console the attacker could read email addresses, force password resets, strip 2FA from targeted accounts, ban users and alter records, including for high-profile creators. He used it to change passwords on two accounts and take their in-game items. Roblox had earlier denied him a bug bounty payout over suspected malicious activity, which appears to have preceded the insider approach.","lessons":"Support consoles that can reset any account need per-record justification, least-privilege scoping and anomaly alerting on bulk or high-profile lookups, so a single bribed agent cannot become a master key.","confidence":"Reported","sources":[{"title":"Hacker Bribed 'Roblox' Insider to Access User Data","url":"https://www.vice.com/en/article/hacker-bribed-roblox-insider-accessed-user-data-reset-passwords/","publisher":"Vice / Motherboard"},{"title":"Hacker Bribed Roblox Worker For Access To Users' Personal Data","url":"https://www.gamespot.com/articles/hacker-bribed-roblox-worker-for-access-to-users-pe/1100-6477149/","publisher":"GameSpot"}],"entry_type":"incident","slug":"2020-hacker-bribed-a-roblox-support-contractor-to-access-user-data-and-reset","year":2020,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-hacker-bribed-a-roblox-support-contractor-to-access-user-data-and-reset"}]}