In September 2023, MGM Resorts disclosed a major cybersecurity incident that disrupted properties and systems. Public actor and incident-response reporting describe LinkedIn reconnaissance followed by a short IT helpdesk call that reset workforce credentials and MFA factors, matching Scattered Spider-style Okta helpdesk-reset tradecraft, then privileged IdP access and ransomware-driven disruption. According to MGM Resorts International’s Form 8-K, the company issued a press release on September 12, 2023 regarding a cybersecurity issue; that filing confirms the incident, not the helpdesk mechanics.

If you want the prevention angle on hardening helpdesk enrollment and recovery so a vishing call cannot re-enroll workforce factors into privileged IdP access, read the related article on mfa2point0.com.

FAQ

How did attackers get into MGM Resorts in September 2023?

Public reporting describes the MGM Resorts September 2023 initial access as helpdesk social engineering, not a normal day-to-day login form steal. Actor claims and incident-response accounts say operators used LinkedIn recon, then a short IT helpdesk call that reset workforce credentials and MFA factors, yielding attacker-controlled authenticators and privileged Okta access before broader disruption. MGM’s Form 8-K confirms a cybersecurity issue involving the company. Public reporting does not establish that the 8-K named the helpdesk call, MFA reset, Okta path, or Scattered Spider.

Did MGM’s 8-K confirm the helpdesk MFA reset?

No. MGM’s Form 8-K does not confirm a helpdesk MFA reset. According to the September 2023 Form 8-K, on September 12, 2023 MGM Resorts International issued a press release regarding a cybersecurity issue, furnished under Item 7.01. Public reporting does not establish helpdesk, MFA factor reset, Okta compromise detail, ransom figures, or exact record counts inside that filing. The helpdesk-plus-reset narrative comes from actor claims and IR reporting that align with known Scattered Spider workforce IdP reset TTPs.

Why didn’t workforce MFA stop this path?

Workforce MFA did not stop the MGM path described in public reporting because the failure was at recovery and re-enrollment, not at proving a password-plus-OTP on a quiet login screen. Helpdesk-driven identity and MFA factor reset after social-engineering proofing replaces the legitimate second factors with attacker-held ones. OTP, push, SMS, email codes, and similar transferable factors can be re-issued when support is talked into a reset. After that, sessions and SSO access follow authentication with those attacker-bound factors. MFA does not undo ransomware or property outages once privileged access already exists. Closing the phishable recovery path stops this path. Malware after a legitimate login is a harder, separate problem. A fix that hardens enrollment and recovery exists; the companion covers it without rehashing the outage timeline.

Is helpdesk vishing different from a fake login page?

No. For the MGM Resorts case class, helpdesk recovery vishing and coached fake-login social engineering are the same attack class. A technician talked into handing over a reset, a temporary access secret, or a new MFA enrollment is the same live coaching of a transferable factor as an employee talked into typing a password, approving a push, or adding a device on a spoofed page. Public reporting on MGM describes the helpdesk recovery path, not a documented device-code flow. Both paths abuse identity lifecycle steps that still accept phishable proof. The two industrial vishing paths fail for the same reason: transferable factors at enrollment and recovery.

What happened after the identity reset at MGM?

After the reset described in public reporting, privileged Okta access became the foothold for broader disruption at MGM Resorts, with ransomware-driven property and systems outage and corporate plus customer operational effects per filings and press. Session and SSO reach in that narrative follow authentication with attacker-controlled factors rather than a separate pre-auth theft of an already-issued cookie. Once those legitimate-looking IdP sessions exist, containment is revoke, reset, and operational recovery work. Public reporting does not establish a ransom amount or exact affected-record counts. Similar helpdesk password-reset social engineering later hit Marks & Spencer on the workforce identity path.