The article highlights real-world voice-phishing attacks where criminals impersonated employees to persuade help desks to reset passwords or approve Microsoft Entra authentication steps, effectively bypassing MFA. It cites major incidents affecting Las Vegas casinos (including MGM Resorts and Caesars) and Brinks Home, resulting in operational shutdowns, ransom pressure, and large-scale data exposure.
How the attack worked
In these incidents, attackers used voice phishing (vishing) to impersonate employees who claimed to be locked out of their accounts or struggling with multi-factor authentication (MFA). By calling help desks directly and applying urgency, the attackers persuaded support staff to reset passwords or complete authentication steps on their behalf. In one case tied to Scattered Spider, this resulted in casino help desk staff resetting passwords and bypassing MFA entirely. In another case, an attacker talked a help desk employee through completing a Microsoft Entra authentication step, which granted immediate account access.
Why it succeeded
These attacks succeeded because they targeted a human process rather than a technical vulnerability. Help desks are designed to be helpful and responsive, which can make them susceptible to urgency and social pressure. Once a privileged employee is convinced to bypass or approve an authentication step, technical protections like MFA no longer provide their intended security value. As the article notes, the entire security stack can be bypassed if a single privileged employee invites a social engineering attacker across the MFA threshold.
What to watch for
Key red flags identified in these scenarios include:
- Urgency or pressure to skip normal identity verification steps
- Requests to reset passwords or approve MFA changes over the phone
- Being asked to complete or approve an authentication step on behalf of a caller
- Inability to verify the caller's identity through a known internal callback method
- Non-standard or unusual authentication workflows being requested
These patterns appeared across both documented scenarios, where attackers impersonated employees needing urgent account access.
How to build resistance
Organizations can reduce exposure to these tactics by treating help desks and IT support as high-risk targets. This means requiring strong identity verification and an established callback process before any password reset or MFA-related action. Authentication approvals should never be completed on behalf of a caller; they must be tied to the real user and verified through an out-of-band method. Because human defenders cannot always be expected to detect psychologically manipulative trickery, especially as AI-assisted deception becomes more sophisticated, organizations should also consider real-time detection and escalation procedures during live conversations rather than relying on training alone. Building procedures that prevent exceptions under pressure, even for seemingly reasonable requests, is central to closing this gap.
Key findings
- Scattered Spider used vishing while posing as employees to convince casino help desks to reset passwords and bypass MFA.
- MGM Resorts reportedly shut down digital operations for 10 days with an estimated $100M impact; Caesars reportedly faced a $30M demand and is thought to have paid $15M.
- In the Brinks Home incident, the attacker allegedly guided a help desk employee through a Microsoft Entra authentication step to gain immediate access.
- The Brinks Home leak allegedly exposed almost five million customer records and published 41GB of corporate data on a public hacking forum.
- The article argues that real-time, in-conversation detection (including deepfake indicators) may be needed because user training alone is unreliable.
Who’s being targeted
- Commonly targeted roles: Help Desk, IT Support, Identity & Access Management, Security Operations, Finance leadership (for business impact awareness), All employees (vishing awareness).
- Affected industries: Casinos / Hospitality, Home security / Alarm monitoring, Technology / Identity and access management.
- Attack channels: vishing.
- Impersonated: Internal employee (impersonating a casino staff member), Employee needing help with Microsoft Entra sign-in / authentication.
Red flags to watch for
- Urgency/pressure to bypass normal verification steps
- Caller asks for actions that weaken or bypass MFA
- Identity cannot be verified through a known internal callback method
- Request to approve authentication during a live call
- Help desk is asked to act as the user for sign-in steps
- Unusual or non-standard authentication workflow requested
Frequently asked questions
How did attackers bypass MFA using vishing?
Attackers called help desks while impersonating employees, claiming they were locked out, and convinced staff to reset passwords or complete Microsoft Entra authentication steps on their behalf, which bypassed MFA protections.
What industries were affected by these help desk vishing attacks?
The casino and hospitality industry, home security and alarm monitoring companies, and technology or identity access management providers were affected.
Why is help desk verification important against vishing?
Because a single privileged employee who is socially engineered into bypassing verification can undermine an entire security stack, as happened when help desk staff reset passwords or approved authentication steps without confirming caller identity.
Can training alone stop these attacks?
The article argues that human defenders cannot reliably be expected to detect psychologically manipulative trickery, especially as AI-driven deepfake techniques improve, suggesting real-time detection may be needed alongside training.
Read the video transcript
Remember when Las Vegas casinos went dark in 2023? That started with a phone call to the help desk. A caller says, “Hi, this is Alex from Finance, I’m locked out and can’t finish MFA, can you reset my password or approve this Microsoft Entra step right now?” That’s exactly how Scattered Spider hit MGM and how Brinks Home lost almost five million customer records. Here’s the scary part: if the help desk says yes, the entire security stack is bypassed. That one approval can open the door to 10 days of shutdown and multimillion-dollar ransom pressure. So if anyone calls asking you to reset a password or complete an MFA or Entra step while you’re on the phone, stop. Hang up, and call them back using the official internal directory before you touch their account.