TL;DR: Social-engineering attacks can bypass strong security controls when help desks reset passwords and MFA for impersonators, as MGM Resorts’ 2023 breach showed with roughly US$100 million in losses, according to Trusona. The real failure is identity verification at the support layer, where human trust assumptions still outrun zero-trust governance.
NHIMG editorial — based on content published by Trusona: Prevent the Next $100M MGM-Style Breach
By the numbers:
- MGM Resorts International faced a cyberattack that cost the company roughly US$100 million.
Questions worth separating out
Q: What breaks when a help desk can reset MFA after a phone call?
A: The assurance model breaks because the attacker no longer needs to defeat authentication technically.
Q: Why do social engineering attacks still defeat mature IAM programmes?
A: Because many programmes secure the login event but leave recovery, escalation, and exception handling under-governed.
Q: How should security teams reduce the risk of MFA fatigue attacks?
A: Security teams should remove approval-based MFA from high-risk access paths, replace it with cryptographic authentication, and reduce the privileges attached to any successful session.
Practitioner guidance
- Tier account recovery by sensitivity Use separate approval and proofing paths for privileged, finance, and production-facing accounts instead of a single reset script for all users.
- Replace knowledge-based verification Remove security questions from recovery flows and require stronger proofing such as device confirmation, callback validation, or in-person checks for high-risk resets.
- Log and alert on reset abuse patterns Track repeated MFA resets, clustered calls from the same number, and rapid password-plus-factor changes so security teams can investigate before account takeover spreads.
What's in the full article
Trusona's full blog covers the operational detail this post intentionally leaves for the source:
- The exact help-desk verification steps Trusona recommends for stopping impersonation-based resets.
- The specific identity-proofing changes proposed for high-risk account recovery flows.
- The role of phishing-resistant MFA and callback validation in reducing takeover risk.
- The practical workflow guidance for logging, alerting, and escalation when reset abuse is suspected.
👉 Read Trusona's analysis of the MGM-style help desk breach pattern →
MGM-style help desk attacks: are your identity controls ready?
Explore further
Help-desk recovery is now an identity control, not a support convenience. The MGM-style pattern shows that password and MFA reset workflows sit on the critical path of IAM governance. If those workflows accept weak proofing, attackers do not need to break authentication, they simply request a replacement for it. Practitioners should treat recovery approvals as part of the access-control surface, not an administrative back office process.
A few things that frame the scale:
- Enterprises that have experienced a compromised NHI averaged 2.7 separate incidents in the past 12 months, according to The 2024 ESG Report: Managing Non-Human Identities.
- Two-thirds of enterprises have endured a successful cyberattack resulting from compromised non-human identities, according to The 2024 ESG Report: Managing Non-Human Identities.
A question worth separating out:
Q: Who is accountable when a third-party help desk is tricked into granting access?
A: The enterprise remains accountable for the access it delegates, even when a third-party desk performs the action. Outsourcing does not outsource identity risk. Governance, verification standards, audit rights, and offboarding responsibilities need to be defined contractually and enforced operationally.
👉 Read our full editorial: Help desk social engineering bypasses MFA in MGM-style breaches