The MGM Breach Wasn't a Hack. It Was a Ten-Minute Phone Call episode artwork

EPISODE · Jul 26, 2026 · 17 MIN

The MGM Breach Wasn't a Hack. It Was a Ten-Minute Phone Call

from Blue Team Academy · host Konnio Technology LLC

On Friday, September 8, 2023, someone picked up a phone and called the MGM Resorts IT helpdesk. Ten minutes later, they had Super Admin over one of the biggest identity platforms in the hospitality industry — and MGM was on its way to a $100 million disclosure.This is a Breach Files breakdown of the MGM cyberattack: how Scattered Spider used LinkedIn recon and a vishing call to bypass identity verification, how they turned Okta inbound federation into a permanent backdoor, why MGM's incident response made the damage worse, and what any IT professional can do this week to make sure their own environment isn't the next headline.We walk the whole breach through the Threat & Control Method — Inventory, Threats, Controls, Scale — and end with three concrete audit questions you can take back to work tomorrow.────────────CHAPTERS00:00 The 10-minute phone call00:20 Not a hack. A logon.00:50 Who called MGM02:30 Okta was Tier 004:30 The response that made it worse06:00 The bill: $100M, $45M, 6 TB07:15 The Threat & Control Method09:30 What this means for you10:45 The bottom line────────────Read the full written breakdown:https://blueteam-academy.com/breaches/mgm-cyberattack-anatomy-ten-minute-breach/The Threat & Control Method explained:https://blueteam-academy.com/blog/threat-and-control-method/The Equifax Breach Files (first in the series):https://blueteam-academy.com/breaches/equifax-data-breach-explained/Thinking about moving from IT to cybersecurity? Start here:https://www2.blueteam-academy.com/from-it-to-cybersecurity/Sign up for the Keep IT Safe newsletter (weekly, no fluff):https://www2.blueteam-academy.com/keep-it-safe-signup────────────SOURCES- CISA Advisory AA23-320a — Scattered Spider: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a- Okta Security — Cross-tenant impersonation prevention: https://sec.okta.com/articles/2023/08/cross-tenant-impersonation-prevention-and-detection/- MGM Resorts International — Form 8-K, SEC filing, October 2023- CyberArk — The MGM Resorts Attack: Initial Analysis- U.S. District Court, District of Nevada — In re MGM Resorts International Data Breach Litigation────────────FOLLOW BLUE TEAM ACADEMYInstagram: @blueteamacadLinkedIn: /showcase/blue-team-academyX: @BlueTeamAcadThreads: @blueteamacadCybersecurity is not rocket science.#MGMbreach #MGMcyberattack #ScatteredSpider #cybersecurity #ITtoCyber #blueteam #breachfiles

Episode metadata supplied by the publisher feed · Published Jul 26, 2026

Embed this episode

Ready to play

The MGM Breach Wasn't a Hack. It Was a Ten-Minute Phone Call

0:00 17:47

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Blue Team Academy?

This episode is 17 minutes long.

When was this Blue Team Academy episode published?

This episode was published on July 26, 2026.

Can I download this Blue Team Academy episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!