By NHI Mgmt Group Editorial TeamBased on 1Kosmos: “Unmasking the MGM Resorts Cyber Attack: Why Identity-Based Authentication is the Future” (October 10, 2024)

TL;DR: MGM Resorts’ 2023 breach showed how vishing and help desk impersonation can bypass identity verification, disrupt guest services, and expose customer data, according to 1Kosmos. The incident proves that authentication fails when escalation still depends on human judgment instead of verifiable identity proofing at the service desk.


At a glance

What this is: This is an analysis of the MGM Resorts vishing breach, where help desk impersonation and weak verification controls enabled attackers to disrupt services and expose customer data.

Why it matters: It matters because IAM teams need to treat service desk identity verification as a security control, not an administrative step, especially where human judgment sits inside escalation paths.


Context

The MGM Resorts incident is a classic identity assurance failure, not just a generic security outage. The attack path mattered because the help desk became the point where identity was accepted without sufficient proof, and that acceptance then propagated into service disruption.

For identity programmes, the lesson is broader than one company or one call. When escalation workflows still trust voice-based persuasion, the control boundary sits with people and process, not with the authentication stack alone.


Key questions

Q: What breaks when help desk verification depends on individual agent judgment?

A: Consistency breaks. Different agents will interpret urgency, confidence, and caller behaviour differently, which creates uneven access decisions. Attackers exploit that variance by preparing scripts and applying pressure until they find a lenient interaction. A secure workflow removes that variability and ties account changes to the same evidence every time.

Q: Why do account recovery workflows create authentication risk?

A: Account recovery creates risk because it often reintroduces weaker trust checks such as personal knowledge, help desk scripts, or socially discoverable information. Those steps are built for exceptions and usability, which makes them attractive to attackers. If recovery is easier to abuse than the primary login flow, it becomes the true target of the authentication system.

Q: How can organisations tell if identity proofing is too weak?

A: Look for repeated reliance on one-time checks, inconsistent approvals, and recovery actions that are accepted without strong context. If an attacker could answer the same questions or replay the same evidence across multiple attempts, the proofing model is too easy to stage. Stronger proofing should resist repetition and channel manipulation.

Q: What should organisations do after a service desk impersonation breach?

A: After a service desk impersonation breach, organisations should review every recovery and exception path, revoke any trust shortcuts, and revalidate how identity changes are authorised. The goal is to make sure no support workflow can create access without independently verified proof. That is the fastest way to reduce repeat exposure.


Technical breakdown

Why help desk verification fails under vishing

Vishing works by social pressure, urgency, and context reuse. The attacker does not need to defeat cryptography if the service desk is allowed to treat partial personal information or a confident voice as sufficient proof. In practice, the weak point is not the password reset itself but the human-mediated decision to trust the caller before an identity proofing step is completed. That makes the help desk an authentication extension, not an administrative afterthought.

Practical implication: Treat service desk identity proofing as a hardened control point with scripted verification and no discretionary exceptions.

Why MFA is not enough when escalation is phishable

Multi-factor authentication reduces risk only when the factors resist replay, interception, and social engineering. If a call centre or service desk can be persuaded to reset access, approve a bypass, or enrol a new factor on the wrong basis, MFA becomes a recovery step that attackers can target directly. This is why identity assurance has to extend beyond login into recovery, support, and step-up verification. The control failure is procedural, not purely technical.

Practical implication: Extend phishing-resistant verification into password resets, factor enrolment, and account recovery workflows.

Identity proofing must cover recovery paths, not just sign-in

Identity systems often assume the hardest part is initial authentication, but breach paths frequently enter through recovery. When an actor can convince support staff to override normal checks, the organisation has created a parallel trust channel that bypasses the intended identity lifecycle. In this case, the service desk effectively became an alternate authenticator, which means the actual attack surface included governance over enrolment, recovery, and exception handling, not only end-user login.

Practical implication: Map every recovery and exception path as part of identity governance, then remove any route that cannot be independently verified.


Threat narrative

Attacker objective: The objective was to obtain enough trusted access to disrupt operations and open paths to sensitive customer information.

  1. The attack began with vishing that used social engineering to impersonate a legitimate employee and gain trust from the service desk.
  2. That trust was converted into credential or access-related compromise when the attackers obtained the approvals or resets needed to enter protected systems.
  3. The compromised access then enabled disruption of guest-facing services, manual operational workarounds, and exposure risk for customer data.
  • MGM Resorts breach 2023: A help desk call gave attackers Okta and Azure admin access at MGM, leading to ransomware, ten days of outages and a $100 million hit.
  • Uber breach 2016: An AWS key posted to Uber's private GitHub repositories let intruders copy data on 57 million people; Uber paid $100,000 and hid it for a year.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Help desk identity proofing is now a security boundary, not a support function. The MGM Resorts breach shows that attackers do not need to defeat a primary authentication layer if they can persuade a human gatekeeper to act as one. That shifts risk from login events to recovery and exception handling, where many identity programmes are still weakest. The practitioner conclusion is simple: any workflow that can reset access can also become an attack path.

Identity assurance fails when escalation relies on conversational trust. Vishing attacks succeed because they exploit the mismatch between human judgment and machine-enforced control. The problem is not that staff are careless, but that the process grants them authority without enough verifiable evidence. For identity governance, that means the control model must treat spoken requests as untrusted inputs until independently validated.

Identity verification gaps are often lifecycle gaps in disguise. The breach did not just expose a sign-in weakness; it exposed an offboarding and exception-handling weakness in the broader identity lifecycle. When support desks can override controls without a durable proof trail, organisations lose accountability for who authorised access and why. The practitioner takeaway is that lifecycle governance has to include recovery, enrolment, and administrative exception paths.

Non-phishable recovery paths are the real control objective. The attack demonstrates that the decisive security variable is not how many factors exist, but whether the recovery path can be phished, socially engineered, or manually bypassed. That is where identity programmes need to mature, because an attacker who wins support workflows often wins the account. Practitioners should measure trust at the point of recovery, not only at the point of login.

What this signals

Non-phishable recovery is the governance gap this breach exposes. Many identity programmes still focus on sign-in assurance while leaving resets, enrolment changes, and support overrides under-governed. That leaves a practical gap where an attacker can bypass the strongest authentication method by persuading a human to act as the verifier.

The MGM Resorts case also shows why identity proofing has to be consistent across every channel, not just the customer-facing one. When the service desk can accept voice-based persuasion, the organisation has effectively created a second, weaker authentication system beside the first.


For practitioners

  • Harden service desk identity proofing Require scripted, evidence-based verification for password resets, factor changes, and access recovery, with no discretionary overrides by frontline staff.
  • Remove conversational trust from escalation flows Replace voice-based approval and knowledge-only checks with verifiable proofing steps that cannot be satisfied by urgency, familiarity, or caller confidence.
  • Review account recovery as an attack path Map every reset, enrolment, and support exception path to determine where an attacker could impersonate a user and obtain a privileged action.
  • Separate operational support from identity authority Ensure the people who answer service requests cannot unilaterally authorise identity changes without an independent validation trail.

Key takeaways

  • The breach shows that help desk workflows can become the weakest link when identity verification still depends on human judgment.
  • Operational disruption was immediate and broad, with room keys, slot machines, websites, and manual casino processes affected.
  • Strong recovery controls and verifiable proofing at the service desk are the controls most likely to limit repeat incidents.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationThe breach hinges on weak verification during support-mediated identity changes.
NHI-10 — Human Use of NHIHuman judgment at the service desk was the control surface attackers manipulated.
Recommendation — Harden support workflows to prevent caller-driven identity changes that bypass proofing. Remove human discretion from high-risk identity recovery paths and require verifiable proof.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementAuthenticator resets and changes are central to the incident path.
Recommendation — Apply IA-5 to govern resets, re-enrolment, and lifecycle changes for recovery factors.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe incident exposed weaknesses in how identity-related authorisations were granted and changed.
Recommendation — Restrict authorisation changes to validated workflows with explicit approval evidence.
MITRE ATT&CKTA0006 — Credential AccessVishing was used to obtain the access needed for system compromise and disruption.
TA0001; TA0040 — Initial Access; ImpactThe attack combined initial compromise through impersonation with operational impact.
Recommendation — Map service-desk abuse to TA0006 and monitor for social-engineering-driven credential access. Track impersonation-led entry paths and tie them to downstream impact in detection and response plans.

Key terms

  • Identity proofing: The process of verifying that a person is who they claim to be before granting or restoring access. In higher-risk recovery paths, proofing can include stronger evidence checks such as government ID validation or liveness-based facial verification so the assurance level matches the sensitivity of the request.
  • Support desk escalation: Support desk escalation is the point where a help desk can approve an identity change, reset, or access exception. It becomes a security control when attackers can persuade staff to act on incomplete evidence, which means the workflow itself needs governance and auditability.
  • Phishing-Resistant Identity Verification: Phishing-resistant identity verification is a method that does not rely on shared secrets, one-time passcodes, or knowledge questions that attackers can easily intercept or guess. It uses stronger evidence, often including device-bound or biometric checks, to confirm the person requesting help is the legitimate user. This reduces social engineering risk.
  • Authentication Recovery Path: A governed fallback route that lets a user regain access when their primary factor is unavailable. Recovery is a security control, not just a help desk task, because poorly designed fallback steps can become the easiest way to bypass MFA or create shadow exceptions.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 23, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org