No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

MGM and Caesars Attacks Highlight Social Engineering Risks

November 8, 2023
in Protection
0
informa



The cyberattacks on MGM Resorts International and Caesars Entertainment exposed the widespread effects data breaches can have on an organization — operationally, reputationally, and financially. Although many questions around the specific attack remain, reports say that hackers found enough of an MGM’s employee’s data on LinkedIn to arm themselves with the right knowledge to call the help desk and impersonate the employee, convincing MGM’s IT help desk to obtain that employee’s sign-in credentials.

What is the root cause of this breach? This attack, as well as so many other high-profile breaches over the past few years, happened because of our continued reliance on legacy sign-in credentials like passwords and SMS one-time passcodes that can be easily given away and reused.

Phishing Attacks Aren’t New, but More Successful

Phishing and social engineering attacks to obtain users’ passwords are, of course, nothing new. But now in the age of multifactor authentication (MFA) bypass toolkits and generative AI, these types of attacks have risen in success and popularity with cybercriminals. Attacks can be automated and emails and text messages can appear much more legitimate, which mean more tricked victims. This is what happened with MGM — it takes just a matter of minutes for a hacker to dupe an organization’s help desk into handing over credentials by establishing trust.

In the past, many organizations depended on training to defend against phishing and other social-engineering attacks. These efforts are certainly well-intended, but the fact is that measures like coaching employees to identify poor grammar, misspelled words, and strange spacing as indicators of a phishing email are just not effective in today’s landscape.

The rise of generative AI combined with easily bypassable legacy forms of MFA have created a cybersecurity threat that cannot be trained away. The threat cannot be overcome unless we make the sign-in credentials these cybercriminals so desperately want much harder — if not impossible — to give away.

Authentication Needs More Than Just Passwords

The Cyber Safety Review Board (CSRB) came to a similar conclusion in its recently released report with findings from the Lapsus$ attacks, another string of social engineering attacks that hit large organizations. In its recommendations to protect against similar attacks, the CSRB suggests organizations move to phishing-resistant authentication, namely Fast Identity Online (FIDO) passwordless authentication.

Phishing-resistant authentication uses cryptography techniques that require possession of a device for sign-in or account recovery. This approach ensures that a help desk or other employee (or a family member or friend in consumer settings) cannot give away sign-in credentials even if they fall for a social-engineering attack. Organizations can combine phishing-resistant authentication with more advanced identity verification methods to arm IT departments and help desk employees to truly tell what is a legitimate account lockout and what is an attack.

Considering the high-profile nature of Lapsu$ and these recent ransomware attacks (along with the clear CSRB guidance), any organization that continues to widely rely on passwords and other knowledge-based credentials for user authentication is at best making a questionable choice, and at worst is opening itself up to accusations of corporate negligence.

Organizations must recognize that the cybersecurity landscape has changed dramatically over the past few years and is continuing to rapidly evolve in the age of generative AI. As the MGM breach demonstrates, companies that fail to implement a sound security strategy, starting with eliminating their dependence on passwords and knowledge-based credentials, are taking an unnecessary gamble that they will eventually lose.

Editorial Team

Editorial Team

Related Posts

This $7 Epoxy Putty Saved My Home From Thousands in Water Damage
Protection

This $7 Epoxy Putty Saved My Home From Thousands in Water Damage

April 16, 2026
Why Everyone Is Suddenly Into ‘Combat Training’
Protection

Why Everyone Is Suddenly Into ‘Combat Training’

April 16, 2026
Google’s New Gemini App for Mac Comes With Two Key Benefits (and One Drawback)
Protection

Google’s New Gemini App for Mac Comes With Two Key Benefits (and One Drawback)

April 15, 2026
This 55-Inch LG OLED TV Is Nearly Half Off Right Now
Protection

This 55-Inch LG OLED TV Is Nearly Half Off Right Now

April 15, 2026
Google Is Finally Taking a Stand Against 'Back Button Hijacking'
Protection

Google Is Finally Taking a Stand Against ‘Back Button Hijacking’

April 15, 2026
Spotify Just Partnered With One of Amazon's Best Bookselling Rivals
Protection

Spotify Just Partnered With One of Amazon’s Best Bookselling Rivals

April 15, 2026
Load More
Next Post
Condé Nast Traveler

The 12 Best Bars in Dubai, from Moody Speakeasies to Buzzy DJ Spots

Popular News

  • Are Smartwatches Really Waterproof? | Lifehacker

    Are Smartwatches Really Waterproof? | Lifehacker

    0 shares
    Share 0 Tweet 0
  • Software stocks fall as fear of AI disruption is back in full force

    0 shares
    Share 0 Tweet 0
  • 10 Shows Like ‘Call the Midwife’ You Should Watch Next

    0 shares
    Share 0 Tweet 0
  • The 10 best banks for college students in 2025

    0 shares
    Share 0 Tweet 0
  • OVIX Protocol Falls Victim To $2 Million Oracle Exploit

    0 shares
    Share 0 Tweet 0

Latest News

Chainlink price breaks above compressed SMA ribbon

Chainlink price breaks above compressed SMA ribbon

April 16, 2026
0

Chainlink price is at $9.32 on April 15, up 1.64% on the 4H session, after clearing all four SMAs simultaneously...

Associate Director of Alumni Career Programs

Associate Director of Alumni Career Programs

April 16, 2026
0

Posting DetailsDickinson College is a premier four-year residential liberal arts institution chartered in 1783 and widely recognized as a leader...

This $7 Epoxy Putty Saved My Home From Thousands in Water Damage

This $7 Epoxy Putty Saved My Home From Thousands in Water Damage

April 16, 2026
0

We may earn a commission from links on this page. Ever since our house flooded in the middle of the...

China agrees not to send weapons to Iran, Trump claims amid tensions

China agrees not to send weapons to Iran, Trump claims amid tensions

April 16, 2026
0

Trump announced China agreed not to send weapons to Iran, while Iran’s military warned that continued port blockades violate the...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.