Hackers Who Robbed the Casino with a Phone: MGM Resorts' $100 Million Lesson
March 18, 2026, 2:34 p.m.

"They brought down Las Vegas's largest casino and hotel chain. What did they use as a weapon? A phone and LinkedIn."

In September 2023, MGM Resorts International — the iconic Las Vegas name operating over 30 hotels and casinos — was paralyzed for a full 10 days. Slot machines didn't work, check-in systems crashed, payment terminals locked up. Estimated damage: over $100 million.

So how did this attack happen? Through a technically very simple method: Social engineering.

MGM Resorts sosyal mühendislik saldırısı - telefon ile casino sistemi çöktürüldü

MGM Resorts: Hackers entered the system with a phone — a single call cost $100 million

The Attack That Started on LinkedIn

The attackers — the Scattered Spider (UNC3944) group — first searched on LinkedIn. They found MGM employees and gathered information about a targeted IT employee: their name, job, department.

Then they called MGM's IT help desk. Impersonating the employee, they said:

"Hello, I'm [employee name]. My phone was stolen, I can't access my account. Can you reset my multi-factor authentication?"

The IT help desk reset the MFA without verifying identity. The attackers got in.

10 Days of Chaos

  • 🔴 MGM hotels in Las Vegas and other cities were paralyzed for 10 days
  • 🔴 Slot machines didn't work, guests couldn't check in
  • 🔴 Reservation systems crashed, rooms were assigned manually
  • 🔴 ATMs and payment terminals went offline
  • 🔴 Customer data — including social security numbers — was stolen
  • 🔴 MGM did not pay the ransom — but damages exceeded $100 million

Same Week: Caesars Paid $15 Million

Interestingly, the same group had also hacked Caesars Entertainment using the same method. The difference: Caesars paid half of the $30 million ransom demand ($15 million) and quietly closed the matter.

Lesson: Social engineering is more dangerous than technical vulnerabilities. Because what's exploited is 'trust'. No matter how powerful the technology, humans can be easily manipulated.

Lessons to Learn

  • IT help desk procedures: MFA reset requests should NEVER be completed in a single step. Face-to-face or second-channel verification must be mandatory
  • Identity verification policy: There should be a special, secure process for "phone stolen" scenarios
  • Social engineering awareness training: All IT personnel should be trained against these scenarios
  • LinkedIn and open source intelligence (OSINT) monitoring: How does your company appear from the outside?
  • Phishing simulation: Test your employees periodically

Contact Nordis Global for social engineering tests and employee awareness training.

Similar Posts