MGM Resorts Cyber Attack: How a Lapse in Human Judgement Can Open the Door to Threat Actors

Cliff Martin, GRCI Law’s Head of Cyber Incident Response, comments on the MGM Resorts cyber attack:

“This week has been particularly challenging for MGM Resorts International due to the recent ransomware attack orchestrated by ALPHV/BlackCat. It serves as a stark reminder that no matter how much an organisation invests in technology, a single lapse in human judgement can open the door to threat actors. This incident underscores the critical importance of training employees in cyber security. 

Remarkably, it has been reported that the threat actors managed to breach MGM’s IT environment in just 10 minutes by leveraging a simple social engineering tactic. They used information about an employee on LinkedIn to manipulate the IT help desk into changing their credentials and providing them to the threat actor. The threat actor was then able to use these credentials to gain access into the environment. 

“This breach led to the compromise of all critical IT systems within MGM, resulting in a severe blow to the organisation’s reputation. 

“As aptly pointed out by EvilSec on X (formerly known as Twitter), vishing (voice phishing) has become shockingly prevalent in a landscape where people may not prioritise cyber security.  

“Employees, often with heavy workloads, become susceptible to such tactics, making it alarmingly easy for threat actors to exploit these vulnerabilities. As well as employee training, it is imperative for organisations to establish a robust incident response plan to effectively address cyber security incidents.  

“Regardless of an organisation’s size, it is not a question of ‘if’ but ‘when’ a cyber security incident will happen.  

“Being well prepared is key to minimising an incident’s impact and protecting what is important. The earlier an incident can be detected, the better.”

 Cliff Martin is Head of Cyber Incident Response at GRCI Law


