
Recently it was revealed that guests who were affected by a data leak from an MGM Resort cyberattack in 2023 may be eligible for significant compensation. The final hearing for the settlement is scheduled for June of 2025, awarding victims of the leak up to $50,000 for damages.
"A year and a half and however many millions of dollars of ransom, lost revenue and damage control later, MGM is still cleaning up the mess."
As a reminder, the attack first occurred in September of 2023, crippling resort operations for a week and leaving guests distressed throughout Vegas. MGM had to acknowledge the outage publicly while scrambling to address critical systems issues and compromised passwords. A year and a half later, after many millions of dollars in damages, lost revenue and ongoing damage control, MGM is still cleaning up the mess.
The breach was orchestrated by the hacker group known as Scattered Spider, which employed sophisticated social engineering tactics to infiltrate MGM's system. The attackers used a technique known as vishing, where they impersonated MGM IT staff over the phone to trick employees into providing their credentials and multi-factor authentication reset codes. This allowed the hackers to gain unauthorized access to MGM's internal networks, leading to widespread system outages, including shutting down slot machines, digital room keys, and restaurant point-of-sale systems.
When an attack like this strikes, it's not just the system compromise a company has to worry about, which for a company like MGM can range in the millions of dollars. It puts the company's brand on the line. It puts the company's reputation, its stock price, and years of trust at risk. Simple but seemingly small mistakes by a few well-meaning employees can cost a company its reputation and millions of dollars.
"No organization is immune to social engineering threats."
The incident underscores the reality that no organization is immune to social engineering threats. Despite advancements in technological defenses, human factors remain a critical vulnerability. What makes this even more of a challenge is that cybercriminals evolve like viruses, always targeting the gaps left open in an industry and changing at cyberspeed.

"By working cybersecurity training into employees' everyday workflows, organizations can empower staff with the knowledge and tools to identify potential threats and avoid these kinds of breaches."
This is where we come in. We make cybersecurity training accessible and affordable to organizations of all sizes. We help organizations understand their unique vulnerabilities and how to best train and empower staff with the knowledge and tools to identify potential threats and avoid these kinds of breaches. And we do it in a way that's engaging and effective, using real-world examples and scenarios to create custom solutions based on the specific threats each organization faces. Given the potential repercussions of failing to integrate up-to-date cybersecurity training (reputational damage and financial losses), it's critical to act now. Learn how SavvyShield approaches human risk management as a continuous defense rather than an annual checkbox.



