Quick Answer — In September 2023, MGM Resorts went dark: slot machines froze, hotel keys failed, ATMs stuttered, and the casino floor reverted to paper after a social-engineering intrusion credited to Scattered Spider (an ALPHV/BlackCat ransomware affiliate) cost the company an estimated $100 million of quarterly EBITDAR impact. Days earlier, Caesars had paid a ransom (reportedly ~$15M of a $30M demand) after the same crew hit its loyalty database. The intrusion’s front door was not exotic: a ten-minute vishing call to the helpdesk, finding an overly helpful IT employee. The lesson everyone re-learned at casino volume: your identity helpdesk is a production system with the same uptime and integrity requirements as your database tier.
Two giant hospitality targets breached within days of each other, by voice phishing, in the same quarter the LAPSUS$ verdicts landed — 2023 was the year the industry finally accepted that “people attack people” is a first-class threat model, not a training-video cliché.
What happened
- The initial access: Per reporting, the crew researched an MGM employee on LinkedIn, called the helpdesk posing as them, and persuaded a reset. No malware, no exploit — the credential helpdesk is the exploit.
- The dwell and escalate: The attackers moved into Okta (identity provider) and the broader ESX/hypervisor estate, harvesting privileges before detonating ALPHV ransomware ~2 days later.
- The blast radius: MGM ops degraded for days (slots, room keys, sportsbook app, email); Caesars’ 36M-row loyalty database (incl. IDs and license numbers for some) was exfiltrated instead — two flavors of damage from the same playbook.
- The response divergence: Caesars quietly paid; MGM publicly refused and rebuilt — becoming the case study in the “pay vs. rebuild” debate, complete with SEC filings quantifying the loss.
Scattered Spider’s method, itemized
| Move | Detail |
|---|---|
| OSINT on staff | LinkedIn + data-broker records to build convincing employee impersonation |
| Helpdesk vishing | Urgent, plausible story → password/MFA reset — the single highest-ROI call in intrusions |
| MFA fatigue fallback | If push-spam needed: relentless approval prompts until an exhausted user taps accept |
| Identity-provider pivot | Okta admin compromise turns the IdP into the attacker’s control plane |
| Hypervisor detonation | ESXi mass-encryption to maximize downtime and negotiation leverage |
| Extortion blend | Data-theft leverage (Caesars) or outage leverage (MGM) — whichever the victim’s economics fear more |
Timeline
| Date | Event |
|---|---|
| 2023-08-27 → 09-05 | Caesars Entertainment discloses breach, confirms ransom payment (per SEC filing + reporting), ~tens of millions of loyalty records stolen |
| 2023-09-08 → 09-10 (event) | MGM helpdesk vishing → Okta/AD compromise → ALPHV detonation; outages cascade across Las Vegas and national properties |
| 2023-09-11 (our peg) | MGM confirms cyberattack publicly; SEC 8-K quantifies impact in October ($100M EBITDAR hit, plus ~$10M one-time expenses) |
| 2023-09 → 10 | ALPHV affiliate claims (and fake-claims) MGM; Okta’s own advisory discusses the role of its platform in the intrusion |
| 2023-Q4 → 2026 | The twin attacks harden hospitality + gaming sector security; helpdesk verification vendors boom; Scattered Spider members are progressively identified and arrested through 2024–25 |
Defensive lessons
- The helpdesk is load-bearing security infrastructure. Treat every reset as a privileged access grant: callback verification to registered numbers, manager approval for executive-tier targets, and full recording and replay for audit.
- Number matching alone wasn’t enough — and in 2026 it’s newly insufficient. Push fatigue persisted into 2023 partly because orgs degraded to push-style MFA in corners; number matching and push hardening raise the cost, but the MGM season’s real lesson is to standardize on phishing-resistant factors (FIDO2/passkeys) for admins and helpdesk-adjacent staff first.
- Segment the identity plane. Okta-admin compromise shouldn’t equal hypervisor keys; separate break-glass, scoped admin roles, and hardware-held admin credentials blunt the pivot.
- Rehearse degraded-floor operations. Casinos run on uptime culture; the properties that survived best operationally had paper fallbacks (manual comp slips, physical keycards) drilled like fire drills.
- Decide your ransom stance before the incident. Caesars paid and moved on; MGM refused and ate a quarter’s worth of noise. Both stances are defensible; deciding under duress is not.
The economics-disclosure turning point
The MGM 8-K was a watershed because it converted breach cost from consultant-estimated folklore into a filed number: ~$100M EBITDAR impact and ~$10M remediation spend — inside the very first quarter of the SEC’s new cyber-disclosure regime (Item 1.05 era). Regulators, insurers, and boards all got a calibration point for what a multi-day operational-integrity outage costs a heavy-footprint enterprise — and plaintiffs got a target. The disclosure-era lesson cuts both ways: transparency creates liability surface, but it also creates the only dataset that moves executive behavior. Post-MGM, “what’s our helpdesk verification posture?” became a board-question, asked with a dollar figure attached — and that is the durable outcome of the September that Las Vegas would rather forget.
Why it still matters in 2026
Scattered Spider didn’t stay a casino story: the same actor set hit retail (M&S, Co-op) and insurance globally in 2025, still walking through helpdesks while enterprises chased malware. MGM/Caesars remain the reference incident because they proved the full arc — vishing to IdP to hypervisor to eight-figure loss to filed disclosure — inside one week. Every control recommended since (verified resets, phishing-resistant MFA, admin isolation, degraded-mode drills, pre-decided extortion stances) traces its business-case slide to that week. If your helpdesk still resets an executive on a good story and a caller-ID check, you are running MGM’s September on layaway.
Who exactly is Scattered Spider?
A fluid, mostly Anglophone crew (sometimes tagged UNC3944, “Octo Tempest”, “0ktapus”) known for voice phishing, SIM swaps, and extortion negotiations conducted with a distinctive chaotic online persona — per vendor and law-enforcement reporting, several core members faced arrest and charges through 2024–25.
Why did Okta’s name keep coming up?
Because the intruders used MGM’s identity tier as their control plane, and MGM was an Okta customer; Okta published advisories clarifying that its service hadn’t been breached as a company while detailing how tenant configurations hardened afterward. The nuance matters: the IdP was the cockpit, not the crash.
Did MGM pay the ransom?
Per consistent reporting: no. MGM rebuilt — expensively and publicly. The contrast with Caesars’ reported payment is why the twins remain the standing pay-vs-rebuild comparison in every IR tabletop since.
Could this have been prevented with tech alone?
No — and that’s the point. The front door was a human on a phone. Technology (phishing-resistant MFA, callback protocols, anomaly-scoped admin) shrinks the success window massively, but the deciding control was process discipline at the helpdesk, not an appliance.
Part of the hmmnm.com security-timeline series — one event per month, 2021–2024, indexed here.
