On 11 September 2023, MGM Resorts said a "cybersecurity issue" was affecting some of its systems. Over the following days its website, reservation systems, slot machines, digital room keys and email were disrupted across its properties. The ALPHV (BlackCat) ransomware group took credit, and Reuters reported that the affiliate behind the attack was Scattered Spider. According to vx-underground, which relayed the attackers' account, the way in was simple: find an MGM employee on LinkedIn and call the IT help desk pretending to be them. The attackers said they went on to gain administrator access to MGM's Okta and Azure tenants and encrypted more than 100 ESXi hypervisors. In an SEC filing in October, MGM estimated a negative impact of about $100 million and confirmed that personal information of customers who transacted with it before March 2019 had been stolen. This is a human-identity breach, but it shows how quickly an identity provider becomes the attacker's control plane.
Key takeaways
- Attackers impersonated an MGM employee in a call to the IT help desk, according to the account relayed by vx-underground.
- They said they gained administrator access to MGM's Okta and Azure tenants and later encrypted more than 100 ESXi hypervisors.
- Casino floors, hotel room keys, reservations and the MGM website were disrupted for about ten days.
- MGM estimated a $100 million negative impact and said customer data, including some Social Security and passport numbers, was stolen.
- The identity lesson: a help desk that resets credentials on a phone call can hand over the identity provider, and with it every account.
At a glance
| Organisation | MGM Resorts International (hotel and casino operator) |
|---|---|
| When | September 2023; disclosed 11 September 2023 |
| Attacker | Scattered Spider (UNC3944), an ALPHV (BlackCat) ransomware affiliate, according to Reuters as reported by SecurityWeek |
| Entry point | A call to the IT help desk impersonating an employee found on LinkedIn |
| Identities abused | An employee account; administrator access to Okta and Azure tenants, according to the attackers |
| Impact | About ten days of disruption; about $100 million estimated negative impact; customer personal data stolen |
| Category | Human identity (not listed as an NHI or AI agent breach). Incident class: human-identity breach (help desk social engineering) |
What happened
SecurityWeek reported that the attack "came to light on September 10, and the next day MGM issued a statement saying it was forced to shut down many systems due to a cybersecurity issue." The outage hit MGM's website, casinos, email, restaurant reservations, hotel bookings and "even digital hotel room keys." Vx-underground reported that an ALPHV subgroup had taken credit and described how it got in: "All ALPHV ransomware group did to compromise MGM Resorts was hop on LinkedIn, find an employee, then call the Help Desk. A company valued at $33,900,000,000 was defeated by a 10-minute conversation." SecurityWeek added that Reuters had learned from sources that Scattered Spider, "also known as 0ktapus and UNC3944," was behind the attack.
ALPHV later published its own account. A summary by the University of Hawaii West Oahu says the attackers gained "administrator privileges to MGM's Okta and Azure tenant environments," that ALPHV admitted "to sniffing passwords on their Okta servers," and that MGM shut down its Okta Sync servers to limit the attack. ALPHV said it then "deployed ransomware to more than 100 ESXi hypervisors within MGM's network." These details come from the attackers and have not been confirmed by MGM.
MGM confirmed the cost and the data theft. BleepingComputer reported its 8-K filing of October 2023: "[MGM] estimates a negative impact from the cyber security issue in September of approximately $100 million to Adjusted Property EBITDAR for the Las Vegas Strip Resorts and Regional Operations, collectively." MGM also reported less than $10 million in one-time expenses and said the attackers stole personal information of customers who transacted with it before March 2019, including names, contact details, dates of birth, driver's licence numbers and, for some, Social Security or passport numbers. Netwrix wrote that MGM "stated it never considered paying" a ransom.
Timeline
| Date | Event |
|---|---|
| 10 September 2023 | The attack comes to light, according to SecurityWeek. |
| 11 September 2023 | MGM discloses a cybersecurity issue and shuts down systems. |
| 13 to 14 September 2023 | Vx-underground reports ALPHV's claim; ALPHV publishes its own statement on 14 September. |
| 20 September 2023 | MGM restores its systems, according to Netwrix. |
| 5 October 2023 | MGM notifies affected customers of data theft, according to BleepingComputer. |
| 6 October 2023 | BleepingComputer reports MGM's 8-K estimating an impact of about $100 million. |
How it happened: the identity attack path
- Reconnaissance. The attackers found an MGM employee on LinkedIn.
- Help desk call. They called the IT help desk posing as that employee and obtained access.
- Identity provider takeover. They said they gained administrator access to MGM's Okta and Azure tenants.
- Response and escalation. MGM shut down Okta Sync servers; the attackers said they kept access.
- Ransomware and data theft. More than 100 ESXi hypervisors were encrypted and customer data was stolen.
Impact
- Operations: about ten days of disruption to casinos, hotel keys, reservations, email and websites.
- Money: about $100 million estimated negative impact and less than $10 million in one-time expenses.
- Data: personal information of customers who transacted before March 2019, including some Social Security and passport numbers.
What this means for NHI governance
This is a human-identity breach, flagged as such on our breach hub. The entry point was a person impersonated on the phone. We include it because of where the attackers went next: according to their own account, the identity provider and the directory sync servers that connect it to the rest of the estate. Whoever controls the identity provider can create, reset and federate every account, including service accounts, integrations and the tokens applications rely on.
The central controls are help desk verification that a caller cannot pass with public information, and tight protection of identity provider administrator roles. See our Account Recovery and Help Desk Security Guide and Identity Provider and SSO Security Guide.
Recommendations
- Verify callers before any reset. Use checks an attacker cannot answer from LinkedIn. See our Account Recovery and Help Desk Security Guide.
- Protect identity provider admin roles. Require phishing-resistant MFA and a second approver for admin changes. See the Identity Provider and SSO Security Guide.
- Remove standing admin access. Use just-in-time elevation for Okta and Azure administration. See the JIT Access Guide.
- Alert on identity provider changes. New admins, MFA resets and new federation settings should trigger an immediate response. See the ITDR Guide.
- Plan for losing the identity provider. Keep break-glass accounts and an offline recovery path. See the Break-Glass Account Guide.
Frequently asked questions
How did hackers get into MGM Resorts?
According to the attackers' account relayed by vx-underground, they found an employee on LinkedIn and called MGM's IT help desk pretending to be that person.
Who was behind the MGM attack?
The ALPHV (BlackCat) ransomware group took credit. Reuters reported that its affiliate Scattered Spider carried out the attack.
How much did the MGM cyberattack cost?
MGM estimated a negative impact of about $100 million, plus less than $10 million in one-time expenses, according to its October 2023 SEC filing.
Related NHI Mgmt Group resources
Caesars Entertainment Breach 2023 · Co-op Cyber Attack 2025 · Okta Breach 2023 · Account Recovery and Help Desk Security Guide · Identity Provider and SSO Security Guide
How NHI Mgmt Group can help
An identity provider is the control plane for every human and machine account. We help teams harden help desk processes, protect admin roles and detect identity provider abuse. See our NHI and AI agent security training.
References
- SecurityWeek: Ransomware Gang Takes Credit for Disruptive MGM Resorts Cyberattack (14 September 2023)
- BleepingComputer: MGM Resorts ransomware attack led to $100 million loss, data theft (6 October 2023)
- University of Hawaii West Oahu: ALPHV: Hackers Reveal Details of MGM Cyber Attack (2 November 2023)
- Netwrix: MGM Cyber Attack: What Happened And What It Cost (18 August 2025)