MGM Ransomware Attack: The $100 Million Help Desk Phone Call

Key takeaways
- MGM Resorts International disclosed the incident on September 12, 2023. The company confirmed normal operations on September 20, 2023, after an operating disruption of approximately ten days
- The company reported an approximately $100 million negative impact to Adjusted Property EBITDAR, plus under $10 million in one-time expenses recorded in the third quarter of 2023
- The help desk vector, the ten-minute call, and the hypervisor count all rest on the cyberattackers’ own account and on press reporting rather than on any MGM disclosure
- Okta Security published an advisory describing this exact technique on August 31, 2023, 12 days before MGM disclosed it. The warning was never converted into a control change
- The same access technique produced sector-wide waves across retail, insurance, and aviation through 2025. Qantas disclosed in July 2025 that its own intrusion occurred in a call center
The MGM ransomware attack cost MGM Resorts International approximately $100 million in a single quarter. It reached the company through a simple phone call to its IT service desk.
MGM Resorts International, the casino and hospitality operator behind the Bellagio, the MGM Grand and Aria in Las Vegas, disclosed the incident on September 12, 2023. The company confirmed on September 20, 2023, that all of its hotels and casinos were operating normally.
Cyberattackers linked to the group Scattered Spider reportedly gained access to the company’s identity systems and deployed ALPHV/BlackCat ransomware. Hotel operations were run manually for approximately 10 days across the property portfolio.
The service desk call appears in the threat actor’s own public statement and in press reporting. It appears in no MGM disclosure.
Security teams working to close the same gap can start with security awareness training built for modern social engineering.

MGM Ransomware Attack Quick Facts
| Field | Detail | Source |
|---|---|---|
| Incident | MGM ransomware attack, September 2023 | Form 8-K |
| Date of breach | September 11, 2023 | Iowa Attorney General |
| Publicly disclosed | September 12, 2023, Form 8-K under Items 7.01 and 9.01 | Form 8-K |
| Scope discovered | On or around September 29, 2023 | Iowa Attorney General |
| Threat actor | Scattered Spider, also tracked as Octo Tempest, UNC3944, and 0ktapus, acting as an ALPHV/BlackCat affiliate. Not named in any MGM filing | Microsoft Threat Intelligence |
| Initial access vector | IT service desk social engineering, reported. Not confirmed in any filing | CISA and FBI AA23-320A |
| Systems affected | VMware ESXi virtualization infrastructure is the target class documented for this group. The number encrypted at MGM has never been confirmed | CISA and FBI AA23-320A |
| Data compromised | Name, contact information, gender, date of birth, driver’s license number; Social Security and passport numbers for a limited number of customers | Iowa Attorney General |
| Individuals notified | No verified count published | Iowa Attorney General |
| Ransom paid | Not addressed in any MGM filing | Form 8-K |
| Downtime | Approximately 10 days | Cybernews |
| Reported financial impact | Approximately $100 million to Adjusted Property EBITDAR, plus under $10 million in one-time expenses | Form 8-K |
| Legal outcome | $45 million class action settlement covering the July 2019 and September 2023 incidents | Settlement administrator |
| Free decryptor available | No | No More Ransom |
Several details common to incident profiles of this kind have never been made public in the case of the MGM ransomware attack. MGM Resorts International has not disclosed the encryption method, the file extension appended to encrypted files, the ransom note filename, the amount demanded, or the number of systems encrypted. No regulator filing or court record supplies them.
What Happened in the MGM Ransomware Attack
MGM Resorts International is a global gaming and entertainment company that reported consolidated net revenues of $13.1 billion for the full year 2022. Of that total, $8.4 billion came from its Las Vegas Strip resorts.
The company operated ten Las Vegas Strip resorts, including Bellagio, Aria, MGM Grand Las Vegas, and Mandalay Bay, along with eight regional casino resorts. It employed approximately 46,000 full-time and 18,000 part-time staff domestically.
That scale made the company reachable. Tens of thousands of employee identities existed, all of them resettable through a single support function.
MGM Resorts International disclosed the MGM ransomware attack on September 12, 2023. The statement stated that the company had recently identified a cybersecurity issue affecting certain of its systems, had begun an investigation with leading external cybersecurity experts, and had notified law enforcement.
That statement named no threat actor, entry point, or scope. The company has not named the group in any filing since.
The documented access route for this group runs through people and processes. CISA and the FBI reported in November 2023 that Scattered Spider impersonated company IT and help desk staff over the phone to obtain employee credentials. The same advisory records that the group convinced IT help desk personnel to reset passwords and MFA tokens.
Microsoft Threat Intelligence documented the same crew, which it tracks as Octo Tempest and which overlaps with Scattered Spider and 0ktapus. The group called a company help desk and socially engineered it into resetting a user’s password, then added or changed a multi-factor authentication factor.
In mid-2023, that group became an affiliate of ALPHV/BlackCat, a ransomware-as-a-service operation. It concentrated its payloads on VMware ESXi servers.
Operations across the property portfolio were disrupted for approximately ten days. On September 20, 2023, the company stated that all of its hotels and casinos were operating normally. Employees were on hand to help guests with intermittent issues.
MGM Ransomware Attack Timeline
Most accounts of the MGM ransomware attack collapse four separate events into one date. The intrusion, the disclosure, and the point at which MGM Resorts International established what data had been taken are each fixed by a filing.
Those events fall three weeks apart, and the moment of detection appears in no filing at all.
| Date | Event | Source |
|---|---|---|
| August 31, 2023 | Okta Security publishes an advisory describing service desk MFA resets and second identity provider impersonation | Okta Security |
| September 11, 2023 | The date MGM Resorts International records as the date of the data breach | Iowa Attorney General |
| September 12, 2023 | MGM Resorts International discloses a cybersecurity issue affecting certain systems | SEC Form 8-K |
| September 20, 2023 | MGM Resorts International states that all of its hotels and casinos are operating normally | Cybernews |
| On or around September 29, 2023 | MGM Resorts International discovers the scope of the data affected | Iowa Attorney General |
| October 5, 2023 | MGM reports an approximately $100 million impact and begins notifying customers by email | SEC Form 8-K |
| November 16, 2023 | CISA and the FBI publish joint advisory AA23-320A on Scattered Spider | CISA |
| December 19, 2023 | The Justice Department announces the disruption of ALPHV/BlackCat | US Department of Justice |
| February 20, 2024 | MGM Resorts International petitions to quash or limit an FTC civil investigative demand | Federal Trade Commission |
| August 21, 2025 | Noah Michael Urban is sentenced to 10 years in federal prison with $13 million in restitution | US Department of Justice |
| December 12, 2025 | Cash settlement payments are sent to approved claimants | Settlement administrator |
| January 29, 2026 | Nevada Gaming Commission Regulation 5.260 is adopted and takes effect | Nevada Gaming Commission |
| April 2026 | Tyler Robert Buchanan pleads guilty to conspiracy to commit wire fraud and aggravated identity theft | Help Net Security |
| July 16, 2026 | Thalha Jubair and Owen Flowers are each sentenced to five years and six months for the attack on Transport for London | National Crime Agency |
August 31, 2023: The Warning That Preceded the Breach
Twelve days before MGM Resorts International disclosed its incident, Okta Security published an advisory describing the technique that would be used against it.
The advisory recorded that the caller’s strategy was to convince service desk personnel to reset all multi-factor authentication factors enrolled by highly privileged users. The threat actor was then observed configuring a second identity provider to act as an impersonation app. That provider was then used to access applications within the compromised organization on behalf of other users.
That sequence is the MGM attack chain, published before the attack became public.
September 11 and September 29, 2023: The Two Dates the Filings Fix
MGM Resorts International has never filed a start date for the intrusion. Its notice to state regulators records the data breach as occurring on September 11, 2023, and the scope as discovered on or around September 29, 2023. Eighteen days therefore separate the breach from the company establishing what had been taken.
The widely repeated account of a single short phone call preceding those dates originates with the alleged attacker. No investigator has corroborated it, and this article treats it as a claim.
How Did the MGM Ransomware Attack Work?
Five ordinary steps in the MGM ransomware attack were each allowed to succeed, and no software exploit appears anywhere in the chain. Each step below names the control that should have interrupted it.
The details come from CISA, the FBI, and Microsoft Threat Intelligence, as MGM Resorts International has published no technical account of its own.
Step 1: Open-Source Reconnaissance on Professional Networks
The control that fails here is the verification question itself. Microsoft Threat Intelligence reported that the group researches organizations and identifies targets to impersonate victims. That research covers phone calls and personally identifiable information used to trick technical administrators.
Every fact a service desk asks for sits on the public record: full name, job title, reporting line, office location, and start date.
Step 2: Pretexting the IT Service Desk by Phone
The escalation path fails at this step, because the agent has none. CISA and the FBI classify the technique as spearphishing voice (T1566.004), a category better known as voice phishing, or vishing.
A tier-one agent, measured on how quickly tickets close, speaking to a caller who sounds senior, urgent, and well-informed, has no procedure that makes refusal the safe choice. The process handed that agent the authority to say yes and to cover for saying no.
Step 3: Credential and MFA Reset
Separation of duties is what breaks at this step. CISA and the FBI recorded that Scattered Spider convinces IT help desk personnel to reset passwords and MFA tokens, cataloged as T1556.006. Microsoft Threat Intelligence recorded an adjacent route in which control of an employee’s phone number completes a self-service password reset.
One agent able to reset both a password and a second factor collapses the authentication model into that conversation. The wider pattern is set out in Adaptive Security’s guide to MFA bypass attacks.
Step 4: Identity Provider Persistence Through a Second IdP
The control that fails here is detection, because the change generates almost no noise. Microsoft Threat Intelligence documented the group federating existing domains, or adding and then federating new ones.
The group then abused that federation to generate forged valid Security Assertion Markup Language tokens for any user in the target tenant, carrying claims that multi-factor authentication had been satisfied. Resetting the compromised password does not remove that access, and rebuilding the endpoint does not remove it either.
Step 5: Hypervisor Encryption and Data Exfiltration
Isolation of the virtualization management plane is the last safeguard to fail. CISA and the FBI recorded that Scattered Spider exfiltrates data to sites including United States-based data centers and MEGA.NZ and has deployed BlackCat/ALPHV ransomware to encrypt VMware ESXi servers.
One action at the hypervisor layer reaches every virtual machine running on the host. MGM Resorts International has never confirmed how many of its systems were encrypted.
Mapping the MGM Attack Chain to MITRE ATT&CK
Every technique identifier below comes from the MITRE ATT&CK tables published in CISA and FBI advisory AA23-320A.
| Step | Technique | ID |
|---|---|---|
| Step 1: Reconnaissance | Gather Victim Identity Information | T1589 |
| Step 1: Reconnaissance | Phishing for Information | T1598 |
| Step 2: Pretexting by phone | Phishing: Spearphishing Voice | T1566.004 |
| Step 2: Pretexting by phone | Impersonation | T1656 |
| Step 3: Credential and MFA reset | Modify Authentication Process: Multi-Factor Authentication | T1556.006 |
| Step 3: Credential and MFA reset | Valid Accounts: Domain Accounts | T1078.002 |
| Step 3: Adjacent technique | Multi-Factor Authentication Request Generation | T1621 |
| Step 4: Identity provider persistence | Domain Policy Modification: Domain Trust Modification | T1484.002 |
| Step 4: Identity provider persistence | Forge Web Credentials | T1606 |
| Step 5: Exfiltration | Exfiltration Over Web Service: Exfiltration to Cloud Storage | T1567.002 |
| Step 5: Encryption | Data Encrypted for Impact | T1486 |
Who Was Responsible for the MGM Ransomware Attack?
Attribution for the MGM ransomware attack rests on two different records, and each establishes something different. Government advisories and charging documents establish the group's existence, methods, and criminal conduct without naming MGM Resorts International.
The link between that group and this company comes from security reporting.
Aliases, Membership and Operating Model
The US Department of Justice stated on September 18, 2025, that its charges arose from an investigation into a cyber threat group referred to as Scattered Spider, Octo Tempest, UNC3944 and 0ktapus. Microsoft Threat Intelligence describes Octo Tempest as a financially motivated collective of native English-speaking threat actors.
CISA and six partner agencies updated the joint advisory on July 29, 2025. The added co-authors were the Canadian Centre for Cyber Security, the Royal Canadian Mounted Police, the Australian Signals Directorate’s Australian Cyber Security Centre, the Australian Federal Police and the National Cyber Security Centre.
That update also recorded that the group has employed DragonForce ransomware in recent data extortion operations. Neither version of the advisory names a victim organization.
The Affiliate Relationship With ALPHV/BlackCat
Microsoft Threat Intelligence reported that, in mid-2023, the group became an affiliate of ALPHV/BlackCat, a human-operated ransomware-as-a-service operation. The group began deploying those payloads by June 2023 and concentrated them primarily on VMware ESXi servers.
That division of labor raises the ceiling for both parties. A crew skilled at talking its way into an identity system supplies the access. An established ransomware operation supplies the encryption software, the leak infrastructure and the negotiation apparatus.
The combination puts enterprise-scale extortion within reach of people who could not build the encryption themselves.
Arrests, Pleas and Sentences Through 2026
The prosecution record is substantial, and none of it names MGM Resorts International. On November 20, 2024, the US Attorney’s Office for the Central District of California charged five defendants, including Noah Michael Urban and Tyler Robert Buchanan. The charges covered an SMS phishing scheme that ran from September 2021 to April 2023.
Urban was sentenced to 10 years in federal prison with $13 million in restitution on August 21, 2025, and Buchanan pleaded guilty in April 2026.
The Department of Justice charged Thalha Jubair on September 18, 2025. Those charges covered approximately 120 network intrusions, at least 47 US-based victims, ransom payments of more than $115 million, and a cryptocurrency seizure worth approximately $36 million.
Jubair and Owen Flowers were each sentenced in the United Kingdom on July 16, 2026, for the attack on Transport for London.
The ransomware operation on the other side of the affiliate relationship did not survive either. The Justice Department announced on December 19, 2023 that it had disrupted ALPHV/BlackCat, which had targeted more than 1,000 victims. The same announcement recorded that the FBI had offered over 500 affected victims the capability to restore their systems.
SecurityWeek reported on March 6, 2024, that researchers assessed the operation’s shutdown as an exit scam. Attribution of the MGM ransomware attack to Scattered Spider and ALPHV/BlackCat rests solely on security reporting, as no government record documents the connection.
What Data Was Affected and What Was the Impact of the MGM Ransomware Attack?
Everything in this section on the MGM ransomware attack comes from filings, regulator notices, and the court-approved settlement record. Where a figure circulates widely without a traceable source, it is named as a claim and attributed to whoever made it.

What MGM Reported to the Securities and Exchange Commission
MGM Resorts International quantified the incident once, in an October 5, 2023 filing. The company reported a negative impact of approximately $100 million to Adjusted Property EBITDAR for the Las Vegas Strip Resorts and Regional Operations segments collectively. One-time third-quarter expenses totaled less than $10 million.
The same filing recorded a September occupancy of 88%, down from 93% a year earlier. It also stated that the company does not expect a material effect on its results for the year.
The third-quarter earnings release published on November 8, 2023, put Las Vegas Strip Resorts RevPAR at $216, up from $210. Neither document addresses insurance, though Cybersecurity Dive reported in November 2023 that the chief financial officer expected insurance to cover the costs.
Operational Damage Across the Property Portfolio
The $100 million figure describes earnings. It does not describe what stopped working.
Cybernews reported on September 12, 2023, that MGM websites were down, that guests were unable to use digital room keys and were locked out of their rooms, and that slot machines were taking cash only. The same report recorded that ATMs across the resorts were down and that the MGM Rewards app used for reservations was not working.
Each of those systems earns money by moving a physical person through a physical building, and they went down alongside corporate IT. For most security teams, the worst case is data loss. For a casino operator, it was a guest standing outside a locked hotel room.
Data Exposure and Customer Notification
MGM Resorts International described the affected data in its notice to state regulators dated October 5, 2023: name, contact information, gender, date of birth and driver’s license number. Social Security and passport numbers were affected for a limited number of customers.
The notice states that passwords, bank account numbers and payment card information were not involved. It records that customers who became MGM Resorts clients after February 2019 were not affected in the sensitive categories, and that notifications were sent by email.
No verified count of affected individuals exists for the 2023 incident. Neither the regulator notice nor the October disclosure includes a headcount, and the settlement record combines two incidents.
The $45 Million Class Action Settlement
Tonya Owens et al. v. MGM Resorts International et al., consolidated in the United States District Court for the District of Nevada, resolved claims from two incidents for $45 million. One occurred in or around July 2019 and one in or around September 2023, with final approval on June 18, 2025.
Compensation was tiered at approximately $75 for Social Security or military identification numbers, $50 for passport or driver’s license numbers, and $20 for name, address, or date of birth. Documented losses were claimable up to $15,000, and cash payments were sent on December 12, 2025.
What MGM Confirmed and What the Cyberattackers Claimed
Every cell in the confirmed column traces to an SEC filing or a state regulator notice. Every claim is attributed to the party that made it.
| Subject | What the record confirms | What was claimed |
|---|---|---|
| Entry method | No MGM filing names an entry point, a threat actor, or a vector (Form 8-K) | vx-underground posted that the group found an employee on a professional network and called the help desk, defeating a company valued at $33.9 billion in a 10-minute conversation (SecurityWeek) |
| Systems encrypted | MGM has never stated how many systems were encrypted (Form 8-K) | ALPHV/BlackCat claimed attacks against more than 100 ESXi hypervisors (Cybernews) |
| Timing | Breach recorded as September 11, 2023; scope discovered on or around September 29, 2023 (Iowa Attorney General) | ALPHV/BlackCat claimed it infiltrated on the Friday and deployed on the Sunday (Cybernews) |
| Data taken | Name, contact information, gender, date of birth, and driver’s license number, with Social Security and passport numbers for a limited number of customers (Iowa Attorney General) | ALPHV/BlackCat declined to say whether it had taken personally identifiable information until MGM responded (Cybernews) |
| Ransom | No MGM filing addresses a demand, a negotiation or a payment (Form 8-K) | ALPHV/BlackCat complained publicly that MGM had not contacted it (Cybernews) |
| Caesars payment | No ransom figure appears anywhere in the Caesars filing (Form 8-K) | Unnamed sources told the Wall Street Journal that Caesars paid $15 million against a reported $30 million demand (Cybernews) |
The Ransom Decision: What MGM and Caesars Chose, and What the Filings Confirm
Two companies hit by the same threat actor within days took opposite paths, and the public record supports one account far better than the other. MGM Resorts International absorbed a disruption lasting approximately ten days and has never addressed a ransom in any filing.
Caesars Entertainment disclosed a social engineering attack on an outsourced IT support vendor. The filing states that the unauthorized actor acquired a copy of its loyalty program database including driver’s license numbers and Social Security numbers.
No ransom amount appears in that filing. It states only that the company took steps to ensure the stolen data would be deleted, while noting it cannot guarantee that result.
The $15 million payment and the $30 million demand come from unnamed sources who spoke to the Wall Street Journal. That is the strongest publicly available sourcing, and it falls short of company confirmation.
Neither choice can be scored from outside. What a security leader can do is decide the variables in advance: restoration confidence relative to the systems actually encrypted; exfiltration confidence; regulatory exposure; which clocks start; insurance conditions, including whether the carrier must approve a payment; sanctions screening against the receiving entity; and the limits of any deletion assurance.
Both outcomes are defensible on the public record. Reaching either one for the first time while systems are down is far harder to defend.
MGM Ransomware Attack Recovery and Decryption
No free decryptor exists for the ALPHV/BlackCat ransomware deployed in the MGM ransomware attack. The No More Ransom Project, run jointly by Europol, the Dutch National Police and industry partners, lists no tool for ALPHV or BlackCat. It carries working tools for other families of the same period, including Akira, Avaddon, Babuk and Black Basta.
The FBI developed a decryption tool during the December 2023 disruption and offered it to over 500 affected victims. That tool was never published for general download, and the operation itself shut down in March 2024.
Recovery therefore depends entirely on backups. Because this chain runs from the identity plane to the hypervisor layer, any backup system that authenticates against the same directory as production is reachable using the same stolen credentials.
What Security Teams Should Learn From the MGM Ransomware Incident
The MGM ransomware attack chain had at least six points where a single control would have ended it. None of those controls required technology that did not already exist in 2023.
Each lesson states what failed, why the failure is general, what to change, and how to tell whether the change is working.

Lesson 1: Verification and Reset Authority Both Belonged to One Conversation
Two controls failed together. The service desk verified the caller's identity using facts about the caller, all of which are discoverable. The same agent could then reset a password and re-enroll a second factor in one call.
An agent with both powers has greater privilege than most domain administrators, because that agent can create a working identity for anyone in the directory.
NIST Special Publication 800-63-4 frames the remedy as identity assurance, the robustness of the proofing process used to determine that a person is who they claim to be. NIST treats that assurance as a level to be selected.
Alongside the tiers below, multi-factor re-enrollment and privileged account changes move out of tier one. They move to a second, smaller group with its own approval requirement and a break-glass path that alerts on use.
| Request type | Evidence required | Who approves | Logging obligation |
|---|---|---|---|
| Standard user password reset | Out-of-band callback to the number held in the directory of record | Agent, no escalation | Ticket records the callback and the number dialed |
| Multi-factor authentication re-enrollment | Callback plus manager or sponsor attestation | Named sponsor, recorded in the ticket | Alert raised to the identity team |
| Privileged, administrative or executive account change | Callback, sponsor attestation, and identity document with liveness check where proportionate | Second approver outside the service desk | Full record retained and reviewed within 24 hours |
The callback is the highest-value control on that list, and it fails in three ways. A number can be forwarded, moved via SIM swap, or changed by the caller through a self-service directory update.
The third failure is the one most organizations miss. A callback to a number the cyberattacker edited an hour earlier is a callback to the cyberattacker.
Lesson 2: The Identity Plane Was Neither Alerted Nor Instrumented
Detection and measurement failed together. Adding a second identity provider to a tenant converts a stolen session into durable access and, in most environments, generates no alert. No baseline existed against which a burst of privileged resets would have looked abnormal.
Monitoring effort follows volume, so sign-in logs get attention while federation changes get none. Those changes number a handful per year despite being the higher-fidelity signal.
Any addition or modification of an identity provider or federation trust should raise a priority alert to a named owner. The technique described above produces a configuration that appears legitimate. The second half of the fix is a small service desk metric set, reviewed monthly, with alerting on outliers.
| Metric | What it detects | Suggested starting threshold |
|---|---|---|
| MFA reset rate per privileged account | Repeat targeting of high-value identities | More than one reset per privileged account per quarter |
| Callback completion rate | Verification being skipped under load | Below 98% of eligible resets |
| Mean time to verify | Time pressure shortening the procedure | A sustained fall of more than 25% against the rolling baseline |
| Escalation rate | Agents absorbing decisions they should pass upward | Below 2% of privileged requests |
| Repeated resets on a single account | A cyberattacker retrying after a partial failure | Two or more resets on one account within seven days |
| Resets correlated with new device or impossible travel | A reset immediately preceding anomalous sign-in | Any occurrence |
Those thresholds are proposed operational settings. No published research establishes them as benchmarks, so they should be tuned once 3 months of baseline data are available.
Lesson 3: Virtualization Infrastructure Was Reachable From the Identity Plane
Isolation failed. The path from a help desk conversation to encrypted hypervisors ran without ever leaving the corporate identity domain. Virtualization management is commonly treated as an administration tool when it functions as a control plane, authenticating against the same directory as the email system.
The fix has four parts. Management interfaces move to an isolated segment reachable only from designated administrative workstations. Lockdown mode is enabled on ESXi hosts so operations run through vCenter Server with the documented exception user list reviewed.
Multi-factor authentication is required for virtualization management, using a factor that no service desk can reset, and backups are held immutably outside the identity domain. How modern ransomware operations reach those targets is covered in Adaptive Security’s 2026 ransomware guide.
Lesson 4: Annual Awareness Training Does Not Change Behavior Under Call Pressure
Preparation for the specific moment failed. The agent was asked to refuse an apparently senior colleague under time pressure, with no procedural cover and no training module to prepare for that situation.
The fix is role-specific simulation for the service desk, using voice and synthetic-voice pretexts, measured for refusal and escalation. Ransomware awareness training built for security teams covers how those exercises are structured and scored.
The target behavior is procedural completion regardless of who the caller claims to be. That standard is easier for an agent to meet and harder for a cyberattacker to talk past.
Lesson 5: Outsourced Service Desks Inherit the Gap Without Inheriting the Controls
In the paired incident, the contract failed. Caesars Entertainment disclosed that its compromise resulted from a social engineering attack on an outsourced IT support vendor, the same technique reaching the same authority through a different employer.
Verification standards are written for internal staff and never travel into the contract. Most enterprises run tier one through a managed provider whose agents hold identical reset authority under different rules.
Contractual parity is the fix. The verification procedure, the tiering model, and the metric set become schedule items. Audit rights allow the client to test the provider with authorized pretext calls, and provider agents appear in the same monthly reporting as internal agents.
Lesson 6: The Loss Figure Is the Weakest Argument for the Control
The uncomfortable fact belongs at the front. MGM Resorts International’s own filing stated that it does not expect a material effect on its results for the year. Its chief financial officer expected insurance to cover the costs.
An argument built on the $100 million headline collapses the moment an executive opens the filing. The surviving case has three parts, and no loss figure appears in any of them.
The obligation has changed. Both companies disclosed under general and voluntary filing items before the SEC cybersecurity disclosure rule took effect on December 18, 2023, for larger registrants. An identical incident now requires a materiality determination made without unreasonable delay and an Item 1.05 filing within four business days.
Sector regulators are further compressing the window. Nevada’s Regulation 5.260, effective January 29, 2026, requires notification to the Chair within 24 hours of activating incident response procedures.
Underwriters are assessing the controls in parallel. Insurance Journal reported in May 2025 that identity-related exposures are evaluated through loss control services, naming multi-factor authentication and privileged access among the controls that reduce credential-based attack risk.
A callback to a directory-of-record number costs a service desk roughly two minutes. The documented alternative was ten days of manual operations.
Is the MGM Ransomware Attack Still a Cyberthreat Today?
The MGM ransomware attack remains a live pattern. The same access technique produced sector-wide waves through 2025, and prosecutions were still being handed down through 2026.
The control gap that enabled the original intrusion remains open across most enterprises. Waves of this kind have precedent, and Adaptive Security’s history of notable ransomware attacks traces how earlier strains established the pattern.
| Sector | Organizations | Disclosed detail | Source |
|---|---|---|---|
| Retail, April 2025 | Marks & Spencer | Expected impact of approximately £300 million on 2025/26 operating profit, before cost mitigation, insurance and trading actions | M&S |
| Retail, April 2025 | Co-op and Harrods | Four people arrested by the National Crime Agency in July 2025; the Cyber Monitoring Centre assessed combined impact at £270 million to £440 million | The Hacker News |
| Insurance, June 2025 | Aflac Incorporated | Company stated the unauthorized party used social engineering tactics, as part of a cybercrime campaign against the insurance industry | Aflac |
| Aviation, July 2025 | Qantas | 5.7 million unique customers had data held in the affected system, in an incident the airline states occurred in one of its call centres | Qantas |
The Synthetic Voice Escalation
The economics of the pretext changed in 2025. The FBI’s Internet Crime Complaint Center warned on May 15, 2025, that malicious actors are more frequently exploiting AI-generated audio to impersonate well-known public figures.
The advisory records actors sending AI-generated voice messages that claim to be from senior officials to establish rapport before gaining access to accounts. Adaptive Security’s guide to AI voice cloning scams sets out how those pretexts are built and detected.
Three consequences follow for a service desk. Voice familiarity stops working as a verification signal, because an agent who has heard an executive speak at a company meeting can no longer treat recognition as evidence.
Volume becomes achievable, because a pretext that once required a capable social engineer on a live call can now be produced repeatedly. Pressure tactics also land harder, because a cloned voice carrying a specific executive’s cadence is more persuasive than an unfamiliar one claiming the same authority.
The FBI’s recommended countermeasure is the control this article has argued for throughout. The advisory instructs recipients to independently identify the person's phone number and call to verify their authenticity.
A callback to a number the organization already holds is the one verification step a synthetic voice cannot defeat. It depends on nothing the caller says and nothing the caller sounds like.
A 30, 60, and 90 Day Plan for Closing the Service Desk Gap
The plan below closes the gap left by the MGM ransomware attack and assumes no new tooling budget and no additional headcount. Every control it names already exists in most enterprises and is simply unowned.
Each phase ends with something a security leader can present to a board.
| Phase | Objective | Core actions | Evidence of completion |
|---|---|---|---|
| Days 1 to 30 | Establish exposure | Inventory every role that can reset a password, re-enroll a factor, or change privileges; pull 90 days of reset logs; map privileged accounts reachable through tier one; run an authorized pretext call | A written statement of who can reset what, plus the documented result of the pretext test |
| Days 31 to 60 | Re-engineer verification and authority | Implement the three-tier model with callback numbers sourced from the directory of record; remove privileged reset authority from tier one; instrument identity provider configuration alerts; open contract amendments with outsourced providers | Updated procedure, revised permission sets, a live alert with a named owner, a provider amendment in progress |
| Days 61 to 90 | Test, measure and report | Run vishing simulations against the service desk; run a tabletop on the containment decision; publish the metric baseline; report to the board | Simulation results scored on refusal and escalation, tabletop findings, a published baseline |
The containment tabletop is the part most organizations skip. It covers whether to take systems offline, who authorizes it, what stops when that happens, and what the disclosure clock looks like from that moment on.
MGM Resorts International made that decision live in September 2023, and approximately 10 days of manual operations followed. A control that cannot be reported on has not been implemented.
Frequently Asked Questions About the MGM Ransomware Attack
What Happened in the MGM Ransomware Attack?
MGM Resorts International disclosed a cybersecurity issue on September 12, 2023. In the MGM ransomware attack, cyberattackers linked to Scattered Spider accessed its identity systems via social engineering targeting IT support, and ALPHV/BlackCat ransomware was deployed.
Operations were run manually for approximately 10 days until September 20, 2023.
How Much Money Did MGM Lose From the Cyber Attack?
MGM reported an approximately $100 million negative impact to Adjusted Property EBITDAR across its Las Vegas Strip Resorts and Regional Operations segments, plus under $10 million in one-time expenses. The October 5, 2023 filing stated the company did not expect a material effect on full-year results.
Did MGM Pay the Ransom?
No MGM disclosure addresses a ransom demand, a negotiation, or a payment, and the threat actor complained publicly that MGM had not contacted it. Caesars Entertainment reportedly paid $15 million against a reported $30 million demand, though no figure appears in its own filing.
How Did Hackers Get Into MGM Systems?
Reporting and the attacker’s own account describe open-source research on an employee, followed by a pretext call to the IT service desk. That call produced a credential and multi-factor authentication reset. No MGM disclosure names an entry point, which leaves the help desk vector resting on reporting alone.
Is the MGM Cyber Attack Over?
Operations were restored on September 20, 2023, and the consequences ran into 2026. Settlement payments were sent on December 12, 2025, Nevada Gaming Regulation 5.260 took effect on January 29, 2026, and prosecutions of individuals linked to the group continued through July 2026.
What Was Stolen From MGM Resorts?
MGM’s regulator notice lists name, contact information, gender, date of birth, and driver’s license number, with Social Security numbers and passport numbers affected for a limited number of customers. The company stated that passwords, bank account numbers and payment card information were not involved.
Who Is Scattered Spider?
Scattered Spider is a financially motivated group also tracked as Octo Tempest, UNC3944 and 0ktapus, described by Microsoft Threat Intelligence as a collective of native English-speaking threat actors. It became an ALPHV/BlackCat ransomware affiliate in mid-2023 and specializes in social engineering against IT help desks.
How Long Were MGM Systems Down?
Approximately ten days. MGM Resorts International disclosed the incident on September 12, 2023, and stated on September 20, 2023, that all of its hotels and casinos were operating normally. Employees remained available to assist guests through any remaining intermittent issues.
Was Anyone Arrested for the MGM Ransomware Attack?
Several individuals linked to the group have been prosecuted, though no case in the public record shows a conviction specifically for the MGM incident. Noah Michael Urban received a 10-year federal sentence in August 2025.
Two members were sentenced in the United Kingdom in July 2026 for an attack on Transport for London.
How Much Was the MGM Data Breach Settlement?
$45 million, covering incidents occurring in or around July 2019 and September 2023, consolidated in the District of Nevada. Tiers paid approximately $75, $50, and $20 depending on data sensitivity, with documented losses claimable up to $15,000. Cash payments were sent on December 12, 2025.
Has MGM Been Hacked Before?
Yes. The $45 million class action settlement covers an incident occurring in or around July 2019 alongside the September 2023 attack. No primary source establishes a verified count of individuals affected by either incident, so figures circulating for both should be treated as unconfirmed.
Could the MGM Ransomware Attack Have Been Prevented?
The technique was publicly documented twelve days before disclosure. Okta Security published an advisory on August 31, 2023, describing service desk MFA resets followed by the configuration of a second identity provider for impersonation. An out-of-band callback, or removing MFA reset authority from tier one, would each have interrupted the chain.
Closing Thoughts on the MGM Ransomware Attack
Every control described above existed in 2023, and none of them required new budget or new technology. What was missing was ownership of a phone call: a defined procedure, a callback to a number the organization already held, and a rule that no single agent could reissue both factors of an identity.
Closing that gap is the practical lesson of the MGM ransomware attack. Security awareness training built for modern social engineering is where security teams can begin.
As experts in cybersecurity insights and AI threat analysis, the Adaptive Security Team is sharing its expertise with organizations.
Related articles

AI Email Threat Detection: How It Finds Modern Phishing and BEC and How to Evaluate It Safely at Scale

The Colonial Pipeline Ransomware Attack: A Verified Account of What Happened
