EPISODE · Jul 26, 2026 · 17 MIN
The MGM Breach Wasn't a Hack. It Was a Ten-Minute Phone Call
from Blue Team Academy · host Konnio Technology LLC
On Friday, September 8, 2023, someone picked up a phone and called the MGM Resorts IT helpdesk. Ten minutes later, they had Super Admin over one of the biggest identity platforms in the hospitality industry — and MGM was on its way to a $100 million disclosure.This is a Breach Files breakdown of the MGM cyberattack: how Scattered Spider used LinkedIn recon and a vishing call to bypass identity verification, how they turned Okta inbound federation into a permanent backdoor, why MGM's incident response made the damage worse, and what any IT professional can do this week to make sure their own environment isn't the next headline.We walk the whole breach through the Threat & Control Method — Inventory, Threats, Controls, Scale — and end with three concrete audit questions you can take back to work tomorrow.────────────CHAPTERS00:00 The 10-minute phone call00:20 Not a hack. A logon.00:50 Who called MGM02:30 Okta was Tier 004:30 The response that made it worse06:00 The bill: $100M, $45M, 6 TB07:15 The Threat & Control Method09:30 What this means for you10:45 The bottom line────────────Read the full written breakdown:https://blueteam-academy.com/breaches/mgm-cyberattack-anatomy-ten-minute-breach/The Threat & Control Method explained:https://blueteam-academy.com/blog/threat-and-control-method/The Equifax Breach Files (first in the series):https://blueteam-academy.com/breaches/equifax-data-breach-explained/Thinking about moving from IT to cybersecurity? Start here:https://www2.blueteam-academy.com/from-it-to-cybersecurity/Sign up for the Keep IT Safe newsletter (weekly, no fluff):https://www2.blueteam-academy.com/keep-it-safe-signup────────────SOURCES- CISA Advisory AA23-320a — Scattered Spider: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a- Okta Security — Cross-tenant impersonation prevention: https://sec.okta.com/articles/2023/08/cross-tenant-impersonation-prevention-and-detection/- MGM Resorts International — Form 8-K, SEC filing, October 2023- CyberArk — The MGM Resorts Attack: Initial Analysis- U.S. District Court, District of Nevada — In re MGM Resorts International Data Breach Litigation────────────FOLLOW BLUE TEAM ACADEMYInstagram: @blueteamacadLinkedIn: /showcase/blue-team-academyX: @BlueTeamAcadThreads: @blueteamacadCybersecurity is not rocket science.#MGMbreach #MGMcyberattack #ScatteredSpider #cybersecurity #ITtoCyber #blueteam #breachfiles
Embed this episode
Ready to play
The MGM Breach Wasn't a Hack. It Was a Ten-Minute Phone Call
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.