The 2023 MGM Hack: How a 10-Minute Phone Call Cost the Largest Vegas Operator $100M
On September 10, 2023, a young hacker called the MGM IT helpdesk and pretended to be a locked-out employee. The helpdesk reset their credentials. By morning, MGM was offline globally. The single most expensive social-engineering attack in casino history.
On September 10, 2023, a member of the Scattered Spider hacking group called MGM Resorts' IT helpdesk pretending to be an employee. They had the employee's name from LinkedIn. The helpdesk reset their MFA. Within hours the attackers had Domain Admin. MGM took its own systems offline to contain the breach. Result: 10 days of downtime, $100M in lost revenue, hand-written ledgers at the front desk, and slot machines stuck on demo screens.
September 10, 2023 was a Sunday. By Monday morning every MGM property in Las Vegas was running on paper. Hotel keys didn't work. Slot machines were stuck on demo screens. ATMs at Bellagio were down. Restaurant POS terminals couldn't process credit cards. The booking site was offline. The MGM Rewards app showed errors.
What had happened: a hacker spent 10 minutes on the phone with MGM's IT helpdesk.
The vishing call
"Vishing" — voice phishing — is the simplest form of social engineering. The Scattered Spider group (a loose collective of mostly English-speaking teenagers and young adults) had identified an MGM IT employee on LinkedIn. They knew the employee's name, role, and approximate location.
They called the MGM IT helpdesk and said: "Hi, this is [name], I'm locked out of my account, can you reset my MFA?" The helpdesk asked verification questions. The attacker had researched answers. The helpdesk reset the MFA token to a new device.
The attackers were now logged in as the employee. From there they used internal tools to pivot privileges — eventually reaching Domain Admin in MGM's Active Directory.
Why MGM took itself offline
When MGM's security team detected the intrusion, they had a choice: try to expel the attackers in real time, or shut down the systems entirely. They chose to shut down — the standard response when you're not sure how deep the attackers have gone.
This is why the visible damage was so severe. It wasn't the hackers turning off the slot machines. It was MGM turning off the slot machines because the alternative — letting the hackers stay in the network — was worse.
10 days of paper
For 10 days MGM ran like 1985. Front-desk staff wrote room assignments by hand. Casino floor personnel issued paper markers. Slot ticket-redemption machines were down, so payouts went through the cage with hand-written W2-Gs. Restaurants took cash only.
Caesars, the other major Vegas operator, was hit by the same group around the same time but took a different path. Caesars paid the ransom — reportedly $15M — to restore systems faster. MGM refused.
The MGM-Caesars choice was a public ethics test. MGM took the financial hit on principle. Caesars paid and got back online in days. Both choices have defenders. Neither has a clean answer.
What it cost
MGM disclosed in its Q3 2023 earnings: $100M in lost revenue from the outage. Roughly $10M in legal and remediation costs. An unknown amount in long-term reputational impact. Class-action lawsuits from guests whose data was exposed are still working their way through courts.
Caesars disclosed about $15M in direct ransom plus $25M in remediation.
What this means for players
Three things changed after the 2023 hacks:
- MFA on player accounts. Both MGM Rewards and Caesars Rewards added mandatory two-factor authentication for online accounts in late 2023.
- Stricter ID at the cage. Both operators added secondary ID checks for cage transactions over $10K to prevent attackers from cashing out compromised accounts.
- Helpdesk policy. Casino IT helpdesks no longer reset MFA based on a phone call alone — most now require a video verification or in-person check.
The MGM hack is a reminder that the casino industry, despite the marble lobbies and surveillance cameras, runs on the same Active Directory and Windows infrastructure as a midsize accounting firm. The most expensive technology system in any casino is the slot floor (worth tens of millions in machine inventory and licensing fees). The most expensive single point of failure is the IT helpdesk.
For an industry that has invested billions in physical security — eye-in-the-sky systems, facial recognition, perimeter access — the 2023 hacks were a humbling lesson. The weakest link is still a person on a phone.
Topics
- mgm
- cybersecurity
- industry