---
title: MGM and Caesars Attacks Highlight Social Engineering Risks
metaTitle: "MGM Caesars Attacks Highlight Soc Eng"
slug: mgm-caesars-social-eng
date: "2023-11-08T09:00:00-06:00"
image:
  src: "https://cdn.securelogix.dev/slx/images/mgm-caesars-attacks-highlight-social-engineering-risks.webp"
sourcePublisher:
  name: Dark Reading
  url: www.darkreading.com
sourceArticle:
  url: "https://www.darkreading.com/endpoint/mgm-and-caesars-attacks-highlight-social-engineering-risks"
legacySlug: mgm-caesars-attacks-highlight-social-engineering-risks
tags: [Call Center Fraud, Impostor Scam, MFA, Phishing, Vishing]
status: published
---

## Relying on passwords to secure user accounts is a gamble that never pays off.

The cyberattacks on MGM Resorts International and Caesars Entertainment exposed the widespread effects data breaches can have on an organization — operationally, reputationally, and financially. Although many questions around the specific attack remain, reports say that hackers found enough of an MGM&rsquo;s employee&rsquo;s data on LinkedIn to arm themselves with the right knowledge to call the help desk and impersonate the employee, convincing MGM&rsquo;s IT help desk to obtain that employee&rsquo;s sign-in credentials.

What is the root cause of this breach? This attack, as well as so many other high-profile breaches over the past few years, happened because of our continued reliance on legacy sign-in credentials like passwords and SMS one-time passcodes that can be easily given away and reused...
