No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

MGM and Caesars Attacks Highlight Social Engineering Risks

November 8, 2023
in Protection
0
informa



The cyberattacks on MGM Resorts International and Caesars Entertainment exposed the widespread effects data breaches can have on an organization — operationally, reputationally, and financially. Although many questions around the specific attack remain, reports say that hackers found enough of an MGM’s employee’s data on LinkedIn to arm themselves with the right knowledge to call the help desk and impersonate the employee, convincing MGM’s IT help desk to obtain that employee’s sign-in credentials.

What is the root cause of this breach? This attack, as well as so many other high-profile breaches over the past few years, happened because of our continued reliance on legacy sign-in credentials like passwords and SMS one-time passcodes that can be easily given away and reused.

Phishing Attacks Aren’t New, but More Successful

Phishing and social engineering attacks to obtain users’ passwords are, of course, nothing new. But now in the age of multifactor authentication (MFA) bypass toolkits and generative AI, these types of attacks have risen in success and popularity with cybercriminals. Attacks can be automated and emails and text messages can appear much more legitimate, which mean more tricked victims. This is what happened with MGM — it takes just a matter of minutes for a hacker to dupe an organization’s help desk into handing over credentials by establishing trust.

In the past, many organizations depended on training to defend against phishing and other social-engineering attacks. These efforts are certainly well-intended, but the fact is that measures like coaching employees to identify poor grammar, misspelled words, and strange spacing as indicators of a phishing email are just not effective in today’s landscape.

The rise of generative AI combined with easily bypassable legacy forms of MFA have created a cybersecurity threat that cannot be trained away. The threat cannot be overcome unless we make the sign-in credentials these cybercriminals so desperately want much harder — if not impossible — to give away.

Authentication Needs More Than Just Passwords

The Cyber Safety Review Board (CSRB) came to a similar conclusion in its recently released report with findings from the Lapsus$ attacks, another string of social engineering attacks that hit large organizations. In its recommendations to protect against similar attacks, the CSRB suggests organizations move to phishing-resistant authentication, namely Fast Identity Online (FIDO) passwordless authentication.

Phishing-resistant authentication uses cryptography techniques that require possession of a device for sign-in or account recovery. This approach ensures that a help desk or other employee (or a family member or friend in consumer settings) cannot give away sign-in credentials even if they fall for a social-engineering attack. Organizations can combine phishing-resistant authentication with more advanced identity verification methods to arm IT departments and help desk employees to truly tell what is a legitimate account lockout and what is an attack.

Considering the high-profile nature of Lapsu$ and these recent ransomware attacks (along with the clear CSRB guidance), any organization that continues to widely rely on passwords and other knowledge-based credentials for user authentication is at best making a questionable choice, and at worst is opening itself up to accusations of corporate negligence.

Organizations must recognize that the cybersecurity landscape has changed dramatically over the past few years and is continuing to rapidly evolve in the age of generative AI. As the MGM breach demonstrates, companies that fail to implement a sound security strategy, starting with eliminating their dependence on passwords and knowledge-based credentials, are taking an unnecessary gamble that they will eventually lose.

Editorial Team

Editorial Team

Related Posts

You Can Get a Google Pixel 10 for $250 Off Right Now
Protection

You Can Get a Google Pixel 10 for $250 Off Right Now

April 20, 2026
What 'Running Economy' Actually Means (and How to Improve Yours)
Protection

What ‘Running Economy’ Actually Means (and How to Improve Yours)

April 20, 2026
Apple's Touchscreen MacBook Might Be Delayed
Protection

Apple’s Touchscreen MacBook Might Be Delayed

April 20, 2026
The Best Earbuds You Can Buy Right Now Are on Sale for $300
Protection

The Best Earbuds You Can Buy Right Now Are on Sale for $300

April 20, 2026
Here's Why RAM Prices Won't Be Dropping Anytime Soon
Protection

Here’s Why RAM Prices Won’t Be Dropping Anytime Soon

April 20, 2026
The CRKD Nitro Deck for Nintendo Switch Is on Sale for $35
Protection

The CRKD Nitro Deck for Nintendo Switch Is on Sale for $35

April 20, 2026
Load More
Next Post
Condé Nast Traveler

The 12 Best Bars in Dubai, from Moody Speakeasies to Buzzy DJ Spots

Popular News

  • Government to respond to AJ Bell’s petition after 10,000 signatures

    Government to respond to AJ Bell’s petition after 10,000 signatures

    0 shares
    Share 0 Tweet 0
  • 5 Things to Know About the Pomelo Card

    0 shares
    Share 0 Tweet 0
  • BYD’s annual sales top $100bn for first time

    0 shares
    Share 0 Tweet 0
  • Stock market’s rally to record highs faces these two looming risks

    0 shares
    Share 0 Tweet 0
  • Guide to Content Marketing for Small Businesses

    0 shares
    Share 0 Tweet 0

Latest News

Businesses trying to claim tariff refunds are already running into problems

Businesses trying to claim tariff refunds are already running into problems

April 20, 2026
0

It wasn’t all smooth sailing on Monday as the federal government started the process of accepting claims for massive amounts...

Cardano

Cardano Leadership Structure Comes Under Scrutiny, Clouding Its Future – See Why

April 20, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure In the dynamic blockchain sector, the Cardano...

A Guide to Cycling Paul Revere's Ride to Lexington and Concord, Massachusetts

A Guide to Cycling Paul Revere’s Ride to Lexington and Concord, Massachusetts

April 20, 2026
0

Things to do in Lexington and ConcordThe Minute Man National Historical Park stretches across five miles of the original battle...

You Can Get a Google Pixel 10 for $250 Off Right Now

You Can Get a Google Pixel 10 for $250 Off Right Now

April 20, 2026
0

We may earn a commission from links on this page. Deal pricing and availability subject to change after time of...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.