- Disable User
- Posts
- đ° MGM's unplanned jackpot: Hackers cash in!
đ° MGM's unplanned jackpot: Hackers cash in!
free lessons on verification included

Hi and welcome to another Security weekly. Where we laugh, we cry and share the latest and greatest in security and tech news.
In this week's edition:
đ° MGM's unplanned jackpot: Hackers cash in!
đ° Bits & Bytes
â Disable User explains: Super/Global/Enterprise admin
đ„ meme of the week
Reading time: 02:49

đ° MGM's unplanned jackpot: Hackers cash in!
Thereâs a famous line in the Scorsese movie âCasinoâ:
âWhen you love someone, youâve gotta trust them. Thereâs no other way. Youâve got to give them the key to everything thatâs yours. Otherwise, what's the point?â
And boy, did MGM give away the keyâs to everything.
But before I dive in, why am I writing about this?
Even for us Europeans the MGM Casino is iconic
Lotâs of cybersecurity lessons in this story
Great excuse to use GIFâs and quotes from Oceanâs Eleven & Casino. Jackpot!

Word on the cyber street is that the BlackCatâs affiliate Scattered Spider has pulled a fast one on MGM.
Scattered Spider is a ransomware group that specializes in social engineering attacks. Often employing tactics like impersonating help desk personnel and deploying phishing attacks.
And thatâs exactly what they did:
Went over to LinkedIn to find a MGM employeeâs details
Called the helpdesk, claiming to be the employee in need of a password reset
Helpdesk engineer provided the reset
They broke in.
And they didn't just break in; they encrypted over a hundred of MGMâs ESXi hypervisors, making a high-rolling company hit the digital canvas.

MGM Resorts did what any besieged giant would do: They clammed up.
Not a peep.
You'd think that facing a potential loss of millions and bad PR, they'd be negotiating.
Instead, the cyber gang claims MGM disconnected their Okta Sync servers, a key piece of their IT infrastructure, after figuring out they'd been had.
This of course had massive impact in the casino and the hotel, with ATMâs and digital entrance systems to hotel rooms going offline.
And now?
BlackCat's not sitting still. They've made it clear: pay up, or we'll double down on our attacks.
And theyâre not bluffing. After all, they've got the keys to the kingdom, including MGM's Azure cloud environment.
Will MGM negotiate, or are they hoping for a Hail Mary? All bets are off.

Takeaway? Verification is key.
MGM is a huge company (50 000+ employees), so itâs impossible to know every employee. We canât blame the helpdesk employee per se, but the lack of verification was unmatched.
With that in mind, some tips everyone can use:
Update (or create) verification policies - even when youâre only 50 people. Iâll write an example below.
Never trust, always verify - with AI on the rise, there have been countless impersonations demonstrated. Always verify, even if you think you know who youâre interacting with.
Use multiple verification factors - just like with MFA, use multiple factors
Examples
User calls for a password reset.
Your options:
Let them verify their identity with 3 security questions. Make sure these answers cannot be guessed, or found online.
Make them send an email to confirm. Verified emails only ofcourse.
Perform the change, but send it to their manager/privileged contact. Donât for fall urgency.


Bits & Bytes
Caesars Entertainment confirms ransom payment, customer data theft - MGM wasnât the only casino to get hit.
Google Agrees to $93 Million Settlement in California's Location-Privacy Lawsuit - âOK, fine, we WERE looking through your windows.â
TikTok Faces Massive âŹ345 Million Fine Over Child Data Violations in E.U. - Good for the EU for sticking it to the man, yet I wonder what happens to the money.
NASA clears the air: No evidence that UFOs are aliens - Aww NASA, keep the dream alive yoâ!
When MFA isn't actually MFA - very good read, compelling story

Super/Global/Enterprise admin
The highest level of administrative access in a computer system, allowing full control over all aspects of the system, including sensitive and secure areas.
"Just because you can play God, doesn't mean you should.â
Avoid using/assigning these privileges at all costs, only when there really isnât any other option.


Meme of the week

Funny? Yes. True? Also, yes :(
