/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

MGM was likely hacked by Scattered Spider, an English-speaking group that previously used help desk calls to get passwords and planned to hack the slot machines

Mehul Srivastava / Financial Times :

Financial Times Mehul Srivastava

Context & Ripple Effects

The report arrives while MGM was still dealing with a prolonged disruption: its website had remained unavailable for more than 60 hours after the attack, with ALPHV/BlackCat reportedly claiming responsibility in contemporaneous coverage of the extended MGM outage.

It reframes the incident around identity compromise rather than solely ransomware. Subsequent coverage also characterized Scattered Spider as a young, English-speaking group connected to a broader social-engineering-driven hacking milieu, reinforcing the importance of the initial-access path.

First-order effects

  • MGM must treat employee and help-desk identity verification as a primary containment issue, alongside restoring disrupted digital and casino operations.
  • The reported interest in slot machines expands the incident’s operational stakes from web services to systems tied directly to the guest and gaming experience.

Second-order effects

  • Other hospitality and casino operators face pressure to harden help-desk reset and account-recovery processes, because those workflows can bypass otherwise strong technical controls.
  • Security teams are likely to prioritize privileged-access review and segmentation between corporate identity systems and operational technology, limiting what a compromised employee account can reach.

Third-order effects

  • If similar intrusions continue, cyber resilience in hospitality will increasingly depend on operational identity controls—human verification, access boundaries, and recovery procedures—not just perimeter security.
  • The episode points to a broader shift in which socially engineered access can create enterprise-wide operational risk; the scale of that shift will depend on whether firms redesign their support workflows rather than add isolated controls.

The trend: Social-engineering-led intrusions are making identity and help-desk processes a core resilience issue for companies whose digital systems support physical operations.

Discussion

  • Vox Sara Morrison on x
    The chaotic and cinematic MGM casino hack, explained
  • @vxunderground @vxunderground on x
    All ALPHV ransomware group did to compromise MGM Resorts was hop on LinkedIn, find an employee, then call the Help Desk. A company valued at $33,900,000,000 was defeated by a 10-minute conversation.
  • @vxunderground @vxunderground on x
    When Scattered Spider compromised MGM they tried to modify code for the slot machines to make them spit out money 😂😂 These nerds are going full Ocean's Eleven
  • @_sn0ww Snow on x
    Chances are, if you stopped in the @sec_defcon this year at @defcon, you heard first hand how successful #vishing can be. 🧵
  • @vxunderground @vxunderground on x
    @let_svn No, this isn't an attempt to screw anyone over. This particular subgroup of ALPHV ransomware has established a reputation of being remarkably gifted at social engineering for initial access. It isn't really a surprise ALPHV (or the subgroup) is behind this attack.
  • @racheltobac Rachel Tobac on x
    One of the easiest ways for me to hack is simply: 1. Look up who works at a org on LinkedIn 2. Call Help Desk (spoof phone number of person I'm impersonating) 3. Tell Help Desk I lost access to work account & help me get back in I hope we learn more & get confirmation of methods
  • @vxunderground @vxunderground on x
    @arborbytes The Threat Actors themselves
  • @vxunderground @vxunderground on x
    Very cool. Thank you @Bitdefender and @TrustedSec for the kind words when speaking with @Forbes. However, we would like to note vx-underground is a collective of several people - it is not a single person. (TrustedSec knows this, maybe Mr. Hammerstone made an oopsie doopsie) [ima…