One Phone Call Beat Their Best Defense. It Took Ten Minutes

An MFA bypass attack doesn’t need to break your multi-factor authentication to defeat it. In September 2023, a hacking group proved exactly that against MGM Resorts, and the method they used had nothing to do with cracking any code. In July, I wrote about phishing-resistant MFA and how it closes the gap that let adversary-in-the-middle phishing beat a client’s standard MFA. That’s still true. But I promised to come back to the real limits of even the strongest MFA, and this is the one that has already cost a company nine figures.

How the MGM Resorts MFA Bypass Attack Worked

The hacking group, known as Scattered Spider, spent roughly ten minutes on the phone with MGM’s IT help desk. They impersonated an employee whose name and details they had pulled from LinkedIn, and convinced the help desk to reset that employee’s multi-factor authentication. That single phone call handed them administrator access to MGM’s identity platform. From there they moved through MGM’s systems with credentials nobody had reason to question, because as far as every system was concerned, they were that employee. Slot machines, digital room keys, and reservation systems went dark across more than thirty properties for roughly ten days. MGM later reported the impact at close to one hundred million dollars in a securities filing.

Why This MFA Bypass Attack Beat Phishing-Resistant MFA

MGM’s MFA was not weak. The attackers never tried to defeat it technically. They defeated the process that exists to help someone who has genuinely lost access to their MFA device, a process every organization needs, because people really do lose phones and get new numbers. That recovery process is a second front door, and if it is not held to the same standard as the first one, the strength of the actual login means very little. This is only one of three real limits to phishing-resistant MFA worth knowing. A session can also be stolen by malware already running on a device after MFA has already succeeded, since the token proves the session is real rather than proving who is currently typing. And some systems still allow a fallback to a weaker verification method when the strong one is unavailable, which gives an attacker a door to walk through if they can talk a system, or a person, into using it.

What Actually Stops an MFA Bypass Attack

The fix for the help desk problem is not more technology. The Cybersecurity and Infrastructure Security Agency and the FBI have published joint guidance on this exact attack pattern, recommending that organizations verify identity for any MFA or password reset the way a bank verifies a large wire transfer: a callback to a number already on file, or direct manager approval, using information that cannot be pulled from a public LinkedIn profile. For a small business, that can be one documented rule: nobody resets a login based on a phone call alone. Pair that with monitoring that does not depend on a human getting the verification right every single time. Identity threat detection watches for the login that looks normal on paper but behaves like nobody who actually works there, and flags it before ten minutes turns into ten days. If your provider cannot tell you what happens when someone calls in locked out of their account, ask, and read about what a well-run IT partnership actually looks like month to month.

A phone headset resting on an office desk next to a keyboard, with a padlock icon glowing on a monitor in the background

Back to Blog

Share:

Related Posts

The Number That Broke It

I tested an AI tool this week with the simplest question I…

Read More

The Extension You Probably Did Not Actually Get

Recently I wrote about the cost of not changing, and legacy Windows…

Read More

When They Leave, Do They Take It With Them?

A prospect I met with recently asked me about a much neglected…

Read More