MGM Resorts
A phone call to the IT help desk produced a credential reset. About ten days of disruption followed, all of it starting with a conversation. (Sources: CBS News, AP)
A ten-minute phone call to a help desk took a casino operator offline for ten days. The caller did not exploit anything. They asked for a password reset with enough real detail to sound like an employee, and got one. The incidents below are variations on that call.
A phone call to the IT help desk produced a credential reset. About ten days of disruption followed, all of it starting with a conversation. (Sources: CBS News, AP)
Access inherited through a corporate acquisition with only limited vetting, sitting inside the network long enough to go unnoticed. (Source: ICO penalty notice)
Identity providers and outsourced help desks treated as support functions rather than as the front door they actually are.
At 70% turnover, a property management system that touches everything, and a help desk trained to be helpful, the gap is people and process before it is technology. The technical controls matter, but the phone call comes first.
If any answer is "no" or "I would have to ask", that is the blind spot.
The two-page PDF adds the full account of each incident and the control that would have stopped it. Name and work email, and it comes straight back.
The sector page: identity security for hospitality. The service that closes the gap: security awareness training. And a free audit is 30 minutes with a certified engineer on your own environment, findings in writing: Get a free audit.
Name and work email. The two-page PDF covers each incident in full and the control that would have stopped it.
Needed for the site to work — page delivery, and the spam protection on our forms. These do not track you and cannot be switched off.
Google Analytics and Microsoft Clarity, so we can see which pages are useful and which are confusing. Clarity hides anything you type into a form. We use this to improve the site, not to identify you.
ZoomInfo WebSights, which tells us which organisation a visit is likely to have come from and which pages were read. With this on, ZoomInfo may also set third-party cookies that help it recognise a visit across other websites, and may share that with its own partners. Turning this off stops all of it.