First reportedSeptember 12, 2023
ActivitySeptember 10, 2023
Last updatedFeb 2, 2026, 12:00 AM UTC
Record confidencemed

Key facts

Affected

  • MGM Resorts properties and customers
  • MGM Resorts International (corporate operations and IT systems)

Initial access

  • unknown
  • stolen_creds

Impact

  • service_disruption
  • financial_loss
  • extortion
  • unknown

Attribution

unknown low confidence

Public reporting speculated on actor groups; definitive attribution is not established in the cited SEC filings.

CVEs and ATT&CK

No CVE or ATT&CK association is captured in this curated record.

Mitigations

Now

  • Enforce phishing-resistant MFA for workforce and privileged accountsReduces successful account takeovers from stolen passwords and common social engineering techniques.

Soon

  • Harden helpdesk and password reset workflowsPrevents attackers from using social engineering to reset MFA or regain access via the identity recovery channel.

Later

  • Apply conditional access and session risk controls (device posture, geo, impossible travel)Limits account abuse by requiring stronger signals for high-risk sign-ins and reducing lateral access after compromise.

Detection ideas

Alert on anomalous authentication patterns

Flag first-time device logins, new geo/ASN, impossible travel, and sign-ins immediately followed by privilege escalation or access to sensitive apps.

Data sources: IdP sign-in logs, SSO audit logs, VPN authentication logs

Detect risky account recovery and MFA changes

Alert when MFA factors are reset/added, recovery email/phone is changed, or helpdesk performs high-risk password resets outside normal hours.

Data sources: IdP audit logs, Helpdesk/ticketing logs

Sources