CASE DOSSIER alleged

MGM Resorts Cyberattack (Scattered Spider / ALPHV Vishing Ingress)

Docket: 2:23-cv-01584 Court: U.S. District Court for the District of Nevada Opened: 2023-10-05 Sector: Hospitality, Gaming, Entertainment

Key Facts

Status
ALLEGED
Legal disposition
Loss Amount
$100.0 million
MGM Resorts disclosed a negative adjusted EBITDAR impact of roughly $100 million in its SEC Form 8-K filing.
Techniques
3
Verified mappings
Defendants
0
Named in charges
  • Legal Status: ALLEGED in U.S. District Court for the District of Nevada.
  • Primary Target Sector: Hospitality, Gaming, Entertainment.
  • Documented Financial Loss: $100.0 million.
  • 3 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Sophisticated social engineering and ransomware attack carried out by cybercrime collective Scattered Spider partnering with ALPHV/BlackCat, utilizing a 10-minute phone call to the Okta IT helpdesk to bypass MFA, hijack administrative privileges, and paralyze hotel reservations, digital keys, and casino slot machines.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

A 10-minute social engineering voice phishing (vishing) call to the Okta IT helpdesk impersonating an employee found on LinkedIn, convincing technicians to reset their MFA credentials.

Operational & Financial Fallout

Paralyzed MGM Resorts operations for 10 days, shutting down digital hotel room keys, casino slot machines, ATM cash-out terminals, and online reservation systems across the Las Vegas Strip. MGM incurred a $100 million negative operating earnings impact and $10 million in technology costs.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: ALLEGED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

A 10-minute social engineering voice phishing (vishing) call to the Okta IT helpdesk impersonating an employee found on LinkedIn, convincing technicians to reset their MFA credentials.

Adversary Kill Chain Flow

3 Documented Phases
1
Social Engineering Ingress Helpdesk Vishing and MFA Registration
MITRE ATT&CK T1566.004 →

Scattered Spider operatives called the IT support desk impersonating a corporate employee, successfully convincing the helpdesk technician to enroll an attacker-controlled MFA device.

Artifacts & Tooling: Voice phishing (vishing) LinkedIn employee OSINT
2
Identity Cloud Takeover Okta Super Admin and Azure AD Elevation
MITRE ATT&CK T1078 →

Attackers manipulated identity federation trusts, assigning themselves Global Administrator privileges in Microsoft Azure Active Directory and Super Admin roles in Okta.

Artifacts & Tooling: Okta Identity Cloud tenant takeover Azure AD Global Admin
3
Virtualization Encryption ALPHV/BlackCat ESXi Hypervisor Detonation
MITRE ATT&CK T1486 →

When defenders initiated containment actions, the threat actors retaliated by deploying ALPHV/BlackCat ransomware across VMware ESXi virtual hypervisors, encrypting hundreds of virtual machines simultaneously.

Artifacts & Tooling: ALPHV Linux/ESXi ransomware VMware vSphere console abuse
Real-World Blast Radius & Operational Fallout

Paralyzed MGM Resorts operations for 10 days, shutting down digital hotel room keys, casino slot machines, ATM cash-out terminals, and online reservation systems across the Las Vegas Strip. MGM incurred a $100 million negative operating earnings impact and $10 million in technology costs.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Implement mandatory out-of-band video or manager verification for all helpdesk MFA and password resets.
✓ Transition to FIDO2 phishing-resistant hardware security keys that cannot be phished over the phone.
✓ Restrict ESXi hypervisor management interfaces to isolated out-of-band management subnets.
✓ Enable conditional access rules that detect anomalous location and device changes on administrative accounts.

Procedural & Incident Timeline

2023-09-10 incident

MGM Resorts discovers unauthorized cybersecurity incident and proactively shuts down guest portals and gaming floors.

2023-10-12 filing

MGM Resorts files Form 8-K disclosure detailing $100 million operating income impact and $10 million in one-off technology expenses.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1566.004
"Operatives conducted targeted voice phishing (vishing) calls to the internal IT helpdesk, impersonating an MGM employee identified on LinkedIn to successfully request a password reset and MFA credential registration." CISA & FBI Joint Advisory AA23-320A reviewed
T1078 Valid Accounts
Defense Evasion
"After securing initial access, attackers elevated their privileges into Okta Identity Cloud and Microsoft Azure tenants, establishing super administrator roles to persist across the enterprise." CISA Advisory AA23-320A, Page 4 reviewed
T1486 Data Encrypted for Impact
Impact
"Upon encountering administrative containment attempts by defenders, the threat actors deployed ALPHV/BlackCat ransomware binaries across ESXi virtual machines, shutting down hotel check-in and gaming operations." MGM SEC Form 8-K Filing reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, MGM Resorts Cyberattack (Scattered Spider / ALPHV Vishing Ingress), No. 2:23-cv-01584 (U.S. District Court for the District of Nevada 2023), https://cybercaselibrary.com/cases/mgm-resorts-scattered-spider/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/mgm-resorts-scattered-spider" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>