Breach Breakdown: How the MGM Resorts Cyberattack Happened—and What Could've Stopped It
Published by Synactive Security Team · 5 min read
In September 2023, MGM Resorts International suffered one of the most disruptive cyberattacks in recent years. Hotel room keys stopped working, slot machines went offline, reservation systems failed, and guests experienced widespread service disruptions across multiple properties.
What's striking is that the attackers didn't rely on a sophisticated zero-day exploit. Instead, they exploited a common weakness found in many organizations: identity and human processes.
Let's break down how the attack unfolded and the security controls that could have reduced its impact.
Company Overview
MGM Resorts is one of the world's largest hospitality and entertainment companies, operating casinos, hotels, and resorts across the United States.
Because of its size and reliance on interconnected digital systems, even a brief disruption had significant operational and financial consequences.
Attack Timeline
Phase 1 — Reconnaissance
The attackers gathered publicly available information about MGM employees through sources such as LinkedIn and other online platforms.
Their goal was to identify employees and understand the organization's structure before making contact.
Phase 2 — Social Engineering the Help Desk
Rather than exploiting a technical vulnerability, the attackers reportedly contacted MGM's IT help desk while impersonating an employee.
By providing convincing personal details gathered during reconnaissance, they persuaded support personnel to reset credentials and grant account access.
This single step provided the foothold they needed.
Phase 3 — Initial Access
With valid credentials, the attackers gained legitimate access to MGM's environment.
Since they were using an authorized account, many traditional perimeter defenses were ineffective.
Phase 4 — Privilege Escalation & Lateral Movement
Once inside, the attackers attempted to expand their access by:
- Enumerating Active Directory
- Identifying privileged accounts
- Moving laterally between systems
- Accessing additional credentials and administrative resources
The objective was to maximize control over the environment before detection.
Phase 5 — Business Disruption
The attack affected critical business operations, including:
- Hotel reservation systems
- Digital room key services
- Casino operations
- Payment systems
- Customer-facing applications
The disruption lasted several days and impacted guests across multiple properties.
What Could Have Stopped It?
| Attack Stage | Recommended Controls |
|---|---|
| Reconnaissance | Reduce unnecessary public exposure of employee information and conduct security awareness training. |
| Help Desk Social Engineering | Implement strict identity verification procedures, call-back verification, and phishing-resistant authentication for account recovery. |
| Initial Access | Enforce phishing-resistant multi-factor authentication (MFA) and monitor for anomalous logins. |
| Lateral Movement | Apply least privilege, network segmentation, privileged access management (PAM), and endpoint detection and response (EDR). |
| Business Impact | Maintain tested incident response plans, immutable backups, and rapid containment procedures. |
Key Lessons for Every Organization
Identity Is the New Perimeter
Modern attackers increasingly target users and identity systems rather than firewalls or operating systems.
Security Is More Than Technology
A mature security posture depends on people, processes, and technology working together. Even robust technical controls can be undermined by weak operational procedures.
Help Desk Security Matters
Support teams are a critical part of an organization's security posture. Strong verification procedures can prevent attackers from turning a routine password reset into a major security incident.
Assume Credentials Will Be Compromised
Organizations should design defenses with the expectation that user credentials may eventually be exposed. Controls such as MFA, least privilege, continuous monitoring, and rapid detection help limit an attacker's ability to move through the environment.
Final Thoughts
The MGM breach demonstrates that successful attacks don't always begin with sophisticated malware or unknown vulnerabilities. In this case, the attackers exploited trust, identity, and operational processes to gain access.
For organizations, the takeaway is clear: strengthening identity security, hardening account recovery procedures, and regularly testing people and processes through security assessments can be just as important as patching systems or deploying new tools.
By learning from incidents like MGM's, businesses can identify weaknesses before an attacker does and build a more resilient security program.
Want to test your human processes and identity defenses?
Talk to our security engineers about social engineering and red team assessments.
Get in Touch