The MGM and Caesars Hacks: What a Help Desk Phone Call Teaches Small Businesses

Written by

in

,

By J. Mesa

Slot machines went dark on the Las Vegas Strip this week. Guests at MGM Resorts properties waited in long lines to check in, digital room keys stopped working, and the company’s websites went offline. MGM disclosed a “cybersecurity issue” on September 11. Three days later, Caesars Entertainment told regulators that it, too, had been breached. The early reporting on both cases points to the same weak spot, and it is one your business shares.

What happened at MGM and Caesars?

MGM Resorts. The company announced on September 11, 2023 that it had identified a cybersecurity issue and shut down certain systems to protect them. The outage reached hotels and casinos in several states. As of this writing, MGM is still restoring operations.

Caesars Entertainment. In a filing with the Securities and Exchange Commission on September 14, Caesars disclosed a social engineering attack on an outsourced IT support vendor. The attackers copied data that included the company’s loyalty program database, with driver’s license and Social Security numbers for a large number of members. News outlets report that Caesars paid a ransom of about $15 million. The company’s filing says only that it took steps to ensure the stolen data is deleted and that it can’t guarantee that result.

How did the attackers get in?

MGM has not published the details. Security researchers and news reports attribute the attack to a group known as Scattered Spider, working with the ALPHV ransomware operation, and describe a simple method: the attackers found an employee’s information on LinkedIn, called the IT help desk, posed as that employee, and talked the help desk into resetting access. Treat that account as reported, not confirmed.

Caesars confirmed its own version in writing. The attack began with social engineering of an IT support vendor.

Neither story involves a brilliant piece of code. Both involve a person on a phone who wanted to be helpful.

What is help desk social engineering?

Help desk social engineering is an attack in which a criminal contacts IT support, pretends to be an employee, and asks for a password reset or a new multi-factor authentication device. If the support person agrees, the attacker receives a working login and bypasses every technical control in front of it.

The attacker prepares first. Names, job titles, managers, and office locations come from LinkedIn and company websites. Dates of birth, addresses, and the last four digits of Social Security numbers come from old data breaches. Armed with those, the caller can answer the standard verification questions better than the real employee could.

Who is Scattered Spider?

Scattered Spider is a name researchers use for a loose group of young, native English-speaking attackers who specialize in social engineering. Their known methods include phone calls to help desks, text message phishing aimed at employees, and SIM swapping to intercept verification codes. Their fluency and confidence on the phone set them apart from most ransomware crews.

Why does this matter to a small business?

You may think a casino has nothing in common with a ten-person office. Look at the steps again.

  • An employee’s details were public.
  • Someone with the power to reset passwords took a phone call.
  • That person verified the caller with information a stranger could find.
  • An outside IT vendor held the keys.

Most small businesses match all four. Your “help desk” may be an office manager, a part-time IT person, or a managed service provider with a call center. The question is the same: what does it take to convince that person to reset your password?

How do I protect password resets?

Write a reset procedure and require everyone who can reset credentials to follow it, including your outside IT company.

  1. Call back. Hang up and call the employee at the number on file in your own records. Never use a number the caller supplies.
  2. Verify with something a stranger can’t know. Dates of birth, employee numbers, and manager names fail this test. Use a video call with a manager who knows the person, an in-person visit, or a verification code sent through an internal channel the employee already uses.
  3. Require a second approval for resets of administrator accounts, finance staff, and executives.
  4. Treat multi-factor resets as high risk. Enrolling a new phone or removing a security key deserves a stricter check than a password reset.
  5. Add a delay for privileged accounts where the business can tolerate one.
  6. Log every reset and review the list each week.
  7. Notify the employee by a separate channel each time a reset or a new device enrollment occurs.

Does multi-factor authentication stop this attack?

Only in part. Multi-factor authentication blocks an attacker who holds a stolen password. It does nothing when the help desk enrolls the attacker’s phone as the employee’s new device. The reset process becomes the back door.

Some methods hold up better than others. Text message codes fall to SIM swapping. Push notifications fall to “fatigue” attacks, in which the attacker sends prompts until the employee taps approve. Hardware security keys and number matching resist both. Use the stronger methods for administrators and anyone who handles money.

What should I ask my IT provider?

Caesars was breached through a vendor. Ask yours:

  • How do your technicians verify my employees before a password or multi-factor reset?
  • Who at my company can authorize a reset for an administrator account?
  • Do your own technicians use phishing-resistant multi-factor authentication?
  • How would you detect a new device enrolled on one of my accounts?
  • What do you do in the first hour if you suspect one of my accounts was taken over?

Put the answers in the contract or in a written procedure both sides sign.

How do I reduce what attackers can learn about my staff?

You can’t hide your employees, and you should not try. You can remove the details that make impersonation easy.

  • Keep direct phone numbers, internal titles for IT administrators, and organization charts off the public website.
  • Ask staff with administrator or finance roles to limit what their public profiles reveal about the systems they manage.
  • Never use information found in public records as proof of identity.

What should I train my staff to do?

  • Expect that someone may call pretending to be a coworker, a vendor, or IT.
  • Refuse to read a verification code to anyone, including a caller who claims to be from support.
  • Deny any sign-in prompt they did not start, and report it.
  • Report an unexpected password reset notice at once.
  • Slow down when a caller pushes urgency. A real colleague will wait five minutes for a callback.

Give the help desk the same message from the top: nobody gets in trouble for making the boss wait while they verify. See our cybersecurity training for sessions built around phone-based attacks.

Should a business pay a ransom?

The FBI advises against it. Payment funds the next attack and buys a promise from a criminal. Caesars’ own filing admits it can’t guarantee the outcome. The better investment happens earlier: tested backups, a written incident response plan, and a reset procedure that a confident voice on the phone can’t talk past.

Your next step

Call your own IT support this week and ask them to walk you through how they would verify you for a password reset. If the answer relies on your date of birth or your employee number, you have work to do. Cerberus Cybersecurity writes identity verification procedures and trains teams to resist phone-based attacks. See our services or contact us.