Okta CSO David Bradbury says five client companies, including MGM and Caesars, were hacked via help desk calls by the ALPHV and Scattered Spider groups
Hackers who breached casino giants MGM Resorts International (MGM.N) and Caesars Entertainment (CZR.O) in recent weeks also broke …
Context & Ripple Effects
The casino incidents had already been tied to a social-engineering route: Caesars said an outsourced IT support vendor was targeted in a social-engineering attack on its support provider, while reporting pointed to Scattered Spider’s use of help-desk calls against MGM.
This disclosure broadens that pattern beyond the two casino operators to five Okta clients, tying the incidents to ALPHV and Scattered Spider and making support-desk identity verification central to the breach narrative.
First-order effects
- The five affected Okta clients must treat help-desk interactions as a confirmed intrusion path and review account recovery, password-reset, and agent-verification procedures.
- MGM and Caesars gain a more specific common mechanism for incidents that had already caused extended disruption to MGM’s online presence and a confirmed customer-data theft at Caesars.
Second-order effects
- Identity and IT-support teams at comparable enterprises are likely to tighten escalation and recovery workflows, because a phone-based interaction can bypass otherwise strong technical controls.
- Ransomware groups can reuse a support-desk playbook across multiple targets; that raises the value of vendor and outsourced-support security reviews, as illustrated by Caesars’ outsourced IT-support compromise.
Third-order effects
- If this pattern persists, help desks and account-recovery processes will be treated as part of the identity-security perimeter rather than as a purely operational function.
- The incidents point to a broader shift in ransomware defense: resilience will depend not only on endpoint and network controls, but also on consistently verifying people during high-risk support actions.
The trend: Social-engineering attacks are increasingly concentrating on identity-support workflows, where human-assisted account recovery can become a scalable entry point for ransomware groups.