Picture the Las Vegas Strip at its busiest, and then picture it stopping. In September 2023, slot machines across MGM’s casinos went dark, hotel keycards quit working, guests queued for hours to check in on paper, and one of the largest casino companies on Earth was brought to a standstill. There was no digital masterstroke behind it. There was a phone call, and it lasted about ten minutes.
Key Takeaways
- A roughly ten-minute phone call to MGM’s IT help desk was the entire break-in. The attackers talked their way into a password reset, no malware required.
- The crew was Scattered Spider, young English-speaking social engineers, working alongside the ALPHV/BlackCat ransomware operation.
- The damage was about $100 million in lost earnings and recovery costs, across roughly ten days of disruption.
- MGM refused to pay the ransom. Caesars, hit weeks earlier by the same ecosystem, reportedly paid around $15 million and kept its casinos quiet.
- Nothing here was high-tech. The weak point was a human being trained to be helpful, not a firewall.
How Do You Hack a Casino With a Phone Call?
You do not break in, you talk your way in. The attackers started where every company helpfully publishes its staff list: LinkedIn. They found a real MGM employee, learned enough about them to sound convincing, then phoned MGM’s IT help desk pretending to be that person, locked out and needing a reset. Help desks exist to be helpful, and this one was. It helped.
That reset handed the intruders working credentials, and from there they reached MGM’s Okta identity platform, the system that decides who is allowed into everything else. Once you own the thing that grants access, you own the building. This technique has a name, vishing, short for voice phishing, but the older name fits better: it is a con. What is genuinely modern here is only the target. Identity systems and outsourced help desks have become the soft underbelly of companies that spend fortunes hardening everything else, the same pattern behind the Coinbase breach and the deepfake calls in the Arup scam.
Who Are Scattered Spider?
Scattered Spider is a loose network of mostly young, English-speaking hackers who trade social-engineering tricks the way an earlier generation traded game cheats. Their real weapon is not code, it is a confident voice on the phone. Traditional defenses assume an attacker who writes clumsy, broken-English phishing emails; a calm caller who sounds exactly like a stressed colleague sails straight past them. For the Vegas operations they teamed up with ALPHV/BlackCat, a ransomware-as-a-service crew that supplied the encryption malware once Scattered Spider had done the talking, the same operation that later froze much of US healthcare in the Change Healthcare hack.
| System | What happened during the attack |
|---|---|
| Slot machines | Banks of machines offline or unable to pay out across the Strip |
| Hotel check-in | Manual, handwritten check-ins and hours-long lobby queues |
| Digital room keys | Dead; staff had to escort guests or issue physical keys |
| Website and app | Down for days, with bookings by phone only |
| The ransom answer | MGM refused to pay; Caesars had quietly paid about $15 million |
The Critical Choice
The decision that took down MGM was made in a single moment on that help-desk call: the choice to reset an account’s access on the strength of a convincing voice, with no hard, independent check that the caller was who they claimed to be. Every huge system behind it, the identity platform, the casino floor, the hotel doors, ultimately trusted that one human judgment. When the judgment went the attacker’s way, so did the keys to everything.
That is the uncomfortable lesson of the whole story. MGM had spent enormously on security technology, and none of it mattered, because the break-in did not go through the technology. It went through a person doing their job, being helpful to a stranger who sounded legitimate. A better firewall is not the fix. What is needed is a hard rule that identity is never verified by a phone call alone, no matter how convincing the voice. Until that rule exists, the most expensive security stack in the world still has a ten-minute door.
What Happened Next
MGM absorbed the hit and rebuilt, but the story did not end on the casino floor. Class-action lawsuits followed over the customer data exposed in the breach, and MGM later agreed to a settlement of roughly $45 million. Law enforcement moved on the crew too: over the following year, several alleged Scattered Spider members were arrested across the United States, the United Kingdom and Spain, a rare consequence for a style of attack that usually leaves almost no forensic trail. Caesars, meanwhile, had bought its silence for about $15 million and never made the headlines. Pay quietly and you vanish from the news. Refuse and rebuild, and you become the cautionary tale everyone studies.
Watch the Full Investigation
The video above tells the story in full: the timeline of the outage, the Caesars contrast, and how a con this simple keeps beating billion-dollar companies. For the deeper written breakdown, including the ransom economics and the aftermath, read our full explainer on the MGM hack, and see how the same human weak point runs through every case in the hacks archive. The Strip has recovered. The lesson has not landed yet.