MGM Data Breach

It took less than 10 minutes on a LinkedIn profile and a single phone call to the helpdesk to bring a $14 billion gambling empire to its knees. No zero-days, no complex coding—just a voice on the line and a password reset that changes everything.

So how did that happen???

Analysis with Cyber Kill Chain

1. Reconnaissance

2. Social Engineering

3. Credential Access

4. Persistence

5. Lateral Movement

6. Impact & Objectives

Thoughts

The incident is quite recent (2023), and it shows that social engineering is still very effective. The silver lining? This could have been avoided with better employee awareness and training.

Extended Readings


Last Modified: 2025-12-27 \