If you found this blog post interesting you might also enjoy our regular series of webinars about practical ways to improve the security of people working outside the office.

The 2023 attack on MGM Resorts is often called sophisticated. In one sense it was: it ended in ransomware, days of disruption and an estimated $100 million in cost. But the way in was not sophisticated at all. Someone phoned the IT help desk, claimed to be an employee, and asked for their password to be reset. It worked.

For all the money spent on security tooling, the entry point was a conversation, and a help desk with no reliable way to know who was really on the line.

What happened

In September 2023, a group tracked as Scattered Spider (also known as UNC3944) researched an MGM employee using information available on LinkedIn and elsewhere, gathering enough personal detail to pass basic verification questions. They then called MGM’s IT help desk posing as that employee and persuaded the agent to reset the account’s password and multi-factor authentication. That gave them access to MGM’s single sign-on environment. From there the intrusion escalated, ransomware was deployed by an affiliated group, and MGM’s operations were disrupted for around ten days, with hotel systems, digital room keys and gaming machines affected.

Why it worked

No software vulnerability was exploited. The attackers used publicly available information to impersonate a real employee, and the help desk’s identity checks, the kind of thing an outsider can research or guess, were not strong enough to tell a genuine caller from a convincing impostor. Once the account’s credentials and MFA were reset, the attackers had legitimate access. Everything after that looked, to the systems involved, like an authorised user.

Why existing controls did not catch it

This is the uncomfortable lesson. Multi-factor authentication is meant to stop exactly this kind of account takeover, but it does not help when the help desk itself resets the second factor for the attacker. Endpoint and network tools saw an authenticated user, not an intruder. The failure was at the point of human verification: the help desk had to decide whether the caller was who they claimed to be, and had no reliable way to prove it.

Why it matters for organisations

Help desk social engineering is not an MGM peculiarity. It is a repeatable pattern, and the same technique has since prompted FBI warnings to other sectors, including aviation and insurance. Any organisation with an IT help desk that can reset credentials or MFA over the phone has the same exposure. Attackers favour it because it is cheap, reliable and needs no technical exploit, only a plausible story and enough detail to sound like an employee.

How to reduce the risk

Standard mitigations help: stronger help desk verification procedures, call-backs to known numbers, additional checks before resetting MFA, and staff training. But knowledge-based checks are inherently weak, because the answers, employee IDs, manager names, dates, are often discoverable. The more robust approach is to require something the real employee physically has, rather than something they know and an attacker can research.

How Loxada addresses this

Loxada Verify is aimed directly at this moment. It uses the Loxada router already issued to an employee as a hardware-anchored presence factor, so a help desk can require confirmation tied to a physical device the caller must actually hold, rather than relying on questions an impersonator can answer from public information. Identity resets and other high-risk help desk actions are among its lead use cases.

Verify does not replace your identity provider or help desk processes, and it is not a monitoring tool. What it adds is a way to close the specific gap this breach exploited: a help desk with no reliable means of confirming that the person requesting a reset is really the employee. Loxada Verify launches in Q3 2026.

Common questions

Who is Scattered Spider? A financially motivated group known for social engineering, particularly targeting IT help desks to gain initial access, often working alongside ransomware operators.

How did they get in without malware? By impersonating an employee on a phone call and persuading the help desk to reset the account’s password and MFA, which handed them legitimate credentials.

Would multi-factor authentication have stopped it? Not on its own. The help desk reset the second factor for the attacker, which is precisely how MFA was bypassed.

Is this still a threat? Yes. Help desk impersonation remains a common initial-access technique, with ongoing warnings to multiple sectors.

Sources: MGM Resorts breach, September 2023; reporting on Scattered Spider / UNC3944 and subsequent FBI advisories.

If you found this blog post interesting you might also enjoy our regular series of webinars about practical ways to improve the security of people working outside the office.