
December 6, 2025 • Mary Marshall
Discover how social engineering tactics bypassed MGM security, causing $100M in damages, and learn how IM can prevent similar attacks.
MGM Resorts International, one of the world’s largest casino and hospitality companies, suffered a devastating cyberattack that paralyzed operations across its Las Vegas properties and beyond. What began with a simple phone call to a help desk ultimately resulted in an estimated $100 million in losses.
The MGM breach serves as a sobering reminder of how social engineering can bypass even sophisticated security systems, highlighting critical vulnerabilities in traditional identity management approaches. More importantly, it underscores why enterprises need comprehensive identity security solutions that go beyond conventional password practices.
According to cybersecurity investigations, the MGM breach began with a tactic as old as cybersecurity itself: social engineering. The attackers reportedly posed as an MGM employee, calling the company’s help desk and successfully convincing IT staff to reset credentials, effectively handing over privileged system access.
From there, the attack escalated rapidly:
The financial impact was staggering. MGM later disclosed in SEC filings that the breach cost approximately $100 million in direct losses, with additional reputational damage that’s harder to quantify but potentially even more significant.
At the heart of the MGM breach was a fundamental weakness in identity management practices. Despite investing millions in cybersecurity infrastructure, the company fell victim to one of the most basic attack vectors: inadequate verification of user identities.
According to the cybersecurity firm Mandiant, social engineering attacks like the one that compromised MGM have increased by 33% in the past year alone. These attacks specifically target help desks and IT support staff who have the authority to reset passwords and provide system access.
The MGM breach exposed several critical flaws common in many organizations’ identity management approaches:
The MGM incident is far from isolated. Similar social engineering tactics have compromised other major organizations, including:
A report from Verizon’s 2023 Data Breach Investigations Report found that 74% of breaches involve the human element, including social engineering, errors, or misuse. This statistic highlights a critical truth: technology alone cannot protect organizations without proper identity management protocols.
Organizations can significantly reduce their vulnerability to MGM-style attacks by implementing robust identity management solutions that address the full lifecycle of identity security. Avatier’s Identity Management Services offer comprehensive protection against social engineering and other identity-based threats.
Modern password management solutions go far beyond simple credential storage. Avatier’s Password Management system includes:
These capabilities could have prevented the MGM attack by requiring multiple verification factors before allowing password resets or access to critical systems.
The principle of “never trust, always verify” is essential for preventing lateral movement within networks, which was a critical factor in the MGM breach’s severity.
Avatier’s Access Governance implements zero-trust principles through:
Artificial intelligence and machine learning can identify suspicious behavior patterns that human analysts might miss. Advanced identity management solutions now incorporate:
These capabilities provide an additional layer of security that can detect and block social engineering attempts even when initial defenses are breached.
Technology must be complemented by well-trained personnel. Organizations should:
For organizations looking to avoid becoming the next MGM, implementing a robust identity management strategy requires a multi-faceted approach:
Certain industries, like MGM’s casino and hospitality business, face heightened risks due to their high-value assets and complex operations. Avatier offers specialized solutions for these sectors, including:
Each industry faces unique challenges, but the fundamental principles of strong identity management remain consistent across sectors.
As the MGM breach demonstrates, traditional password-based security measures are increasingly inadequate against sophisticated social engineering attacks. The future of identity security lies in more advanced approaches:
Organizations implementing these forward-looking solutions will be significantly better positioned to resist the sophisticated attacks that compromised MGM and other enterprises.
The MGM Resorts breach offers a costly but valuable lesson: even a single successful social engineering attack can bypass millions of dollars in security infrastructure. The $100 million price tag for this breach underscores the critical importance of comprehensive identity management as the foundation of enterprise security.
By implementing robust password management solutions and comprehensive identity governance, organizations can significantly reduce their vulnerability to similar attacks. More importantly, they can maintain operational continuity and protect both financial assets and customer trust.
In today’s threat landscape, identity has become the new perimeter. The organizations that recognize this reality and implement appropriate identity security measures will be the ones that avoid becoming the next cautionary tale in cybersecurity.
The question is not whether your organization will face social engineering attempts—it’s whether your identity management system is sophisticated enough to stop them before they cause damage. With the right solutions in place, the answer can be a confident yes.