March 18, 2026, 2:34 p.m.
"They brought down Las Vegas's largest casino and hotel chain. What did they use as a weapon? A phone and LinkedIn."
In September 2023, MGM Resorts International — the iconic Las Vegas name operating over 30 hotels and casinos — was paralyzed for a full 10 days. Slot machines didn't work, check-in systems crashed, payment terminals locked up. Estimated damage: over $100 million.
So how did this attack happen? Through a technically very simple method: Social engineering.
MGM Resorts: Hackers entered the system with a phone — a single call cost $100 million
The Attack That Started on LinkedIn
The attackers — the Scattered Spider (UNC3944) group — first searched on LinkedIn. They found MGM employees and gathered information about a targeted IT employee: their name, job, department.
Then they called MGM's IT help desk. Impersonating the employee, they said:
"Hello, I'm [employee name]. My phone was stolen, I can't access my account. Can you reset my multi-factor authentication?"
The IT help desk reset the MFA without verifying identity. The attackers got in.
10 Days of Chaos
- 🔴 MGM hotels in Las Vegas and other cities were paralyzed for 10 days
- 🔴 Slot machines didn't work, guests couldn't check in
- 🔴 Reservation systems crashed, rooms were assigned manually
- 🔴 ATMs and payment terminals went offline
- 🔴 Customer data — including social security numbers — was stolen
- 🔴 MGM did not pay the ransom — but damages exceeded $100 million
Same Week: Caesars Paid $15 Million
Interestingly, the same group had also hacked Caesars Entertainment using the same method. The difference: Caesars paid half of the $30 million ransom demand ($15 million) and quietly closed the matter.
Lesson: Social engineering is more dangerous than technical vulnerabilities. Because what's exploited is 'trust'. No matter how powerful the technology, humans can be easily manipulated.
Lessons to Learn
- ✅ IT help desk procedures: MFA reset requests should NEVER be completed in a single step. Face-to-face or second-channel verification must be mandatory
- ✅ Identity verification policy: There should be a special, secure process for "phone stolen" scenarios
- ✅ Social engineering awareness training: All IT personnel should be trained against these scenarios
- ✅ LinkedIn and open source intelligence (OSINT) monitoring: How does your company appear from the outside?
- ✅ Phishing simulation: Test your employees periodically
Contact Nordis Global for social engineering tests and employee awareness training.
Similar Posts