A look at Scattered Spider, which experts say is a group of 17 to 22-year-old native English speakers likely behind the MGM and 52+ other hacks since March 2022
About a year ago, the U.S. security firm Palo Alto Networks began to hear from a flurry of companies that had been hacked in ways that weren't the norm for cybercriminals.
Context & Ripple Effects
Coverage of the MGM incident had already tied the breach to help-desk password-reset tactics, making the group profile useful as an explanation of how a seemingly ordinary support-channel weakness could be operationalized at scale. The earlier MGM attribution report framed the attack around that specific access path.
This report broadens the issue from a single high-profile victim to an alleged recurring campaign. Later coverage continued to describe the group as using targeted social engineering to enter company networks, reinforcing that identity and support workflows—not only perimeter defenses—are central to the risk.
First-order effects
- MGM and other potential targets face immediate pressure to review help-desk authentication and password-reset procedures, since the reported pattern centers on obtaining access through human-facing processes.
- Security teams gain a more actionable attribution pattern: a young, English-speaking group allegedly linked to dozens of incidents, rather than an isolated breach with unclear methods.
Second-order effects
- Managed security providers and identity vendors are likely to put greater emphasis on controls that verify support requests and detect social-engineering-driven account changes.
- The MGM case raises the cost of weak access recovery processes for enterprises: attackers need not defeat every technical control if they can persuade a service desk to alter credentials.
Third-order effects
- If this pattern persists, cyber resilience will be assessed increasingly through identity-proofing and employee workflows alongside traditional network security.
- The case also illustrates a difficult enforcement gap: even as reporting later said the FBI had identified people connected to the MGM and Caesars breaches, questions remained about the lack of action, leaving companies to reduce exposure before disruption occurs.
The trend: High-impact cyberattacks are increasingly exploiting human identity and support processes as the practical route around hardened technical defenses.