Skip to content
By social engineering

Your Help Desk Is the New Perimeter: What MGM, M&S, and Scattered Spider Taught Every IT Team

Scattered Spider never broke MFA. It phoned the help desk and had MFA moved. What MGM, Caesars, TfL and M&S disclosed, what the Scam Atlas sourced cases show, and a short reset checklist for IT teams.

Your Help Desk Is the New Perimeter: What MGM, M&S, and Scattered Spider Taught Every IT Team, by Deepak Gupta on guptadeepak.com

Attackers no longer need to break multi-factor authentication. They phone the IT help desk, pretend to be an employee, and ask for the password and MFA to be reset. MGM Resorts, Caesars, Transport for London and Marks & Spencer all appear in the public record of this pattern, and the group most linked to it is known as Scattered Spider.

Verified as of 25 September 2026 against the sources linked inline.

I founded LoginRadius in 2013 and scaled it past a billion customer identities. The flow that always needed the most care was never login. It was recovery, because login is a protocol and recovery is a conversation.

What is happening: the phone call that opens the network

The move is simple. A caller rings the service desk, gives a real employee's name and a few personal details, and says they have a new phone. The agent resets the password and moves the MFA to the caller's device. The attacker then signs in as that employee, and single sign-on carries them into everything else.

CISA and the FBI described this in their joint advisory on Scattered Spider, AA23-320A. It says the actors posed as employees. Their goal was to get help desk staff to "reset the employee's password, and transfer the employee's MFA to a device they control." The advisory was first published on 16 November 2023 and last updated on 29 July 2025.

MGM Resorts and Caesars, September 2023

MGM disclosed on 12 September 2023 that it had found a cybersecurity issue and was shutting down some systems. Its Form 8-K of 5 October 2023 estimated a negative impact of about $100 million on Adjusted Property EBITDAR. MGM never said how the attackers got in.

The help desk detail comes from the attackers themselves. TechCrunch reported that Scattered Spider said it found an employee on LinkedIn and called the help desk. The MGM case page marks that detail as a claim, not a company finding.

Caesars was more direct. Its Form 8-K of 14 September 2023 named the cause: "a social engineering attack on an outsourced IT support vendor." The attacker took a copy of the loyalty program database, including driver's licence and Social Security numbers for a significant number of members.

Transport for London, 2024

Transport for London is the case with a court record. Between 31 August and 3 September 2024, attackers made more than 140 systems inoperable and accessed Oyster refunds data, at a reported cost of £29 million. The Register reported that Woolwich Crown Court heard the attackers impersonated an employee and got a TfL helpdesk worker to reset a password.

According to the National Crime Agency, Thalha Jubair and a co-defendant who was a minor at the time pleaded guilty. The CPS reported that each was sentenced on 16 July 2026 to five years and six months.

Marks & Spencer and Co-op, 2025

In April 2025 the attacks moved to UK retail. M&S estimated in its full-year results that the incident would cost about £300 million of 2025/26 operating profit, before mitigation and insurance. Chairman Archie Norman later told MPs that entry came through sophisticated impersonation involving a third party. BleepingComputer reported he said attackers tricked a third party into resetting an employee's password.

Co-op's interim results put its first-half hit at £206 million of lost revenue. Co-op has not published how the attackers got in. The NCA arrested four people in July 2025 over the M&S, Co-op and Harrods attacks.

The US charges

In September 2025 the US Attorney's Office for the District of New Jersey unsealed a complaint charging Thalha Jubair with conspiracies to commit computer fraud, wire fraud and money laundering. It alleges involvement in at least 120 network intrusions and extortion of 47 US entities. It also alleges victims paid at least $115 million in ransom.

The complaint itself describes calls to victims' helpdesks that allegedly got staff to reset other users' passwords. One alleged target was the US Courts network helpdesk, in January 2025. These are allegations, and the US case has not been tried.

Why it matters to you: the help desk is now the weak point

MFA proves that the person signing in holds a registered factor. It says nothing about who registered that factor. The help desk is the one team allowed to change that registration on request. Whoever controls the request controls the account.

That makes your service desk an access control, whether or not anyone designed it as one. Most desks were built to solve problems fast and keep callers happy. That is the wrong goal for a caller you cannot verify.

Your identity questions are public

Many desks still verify callers with date of birth, employee ID, manager's name or the last four digits of a Social Security number. Mandiant, which tracks the group as UNC3944, warns against exactly this. Its hardening guidance says to "avoid reliance on publicly available personal data for verification (e.g., DOB, last 4 SSN)" because the group "often possesses this information." Breach data and LinkedIn have turned these details into public records.

The attacker rehearses your script

CISA's advisory notes that the social engineering "frequently occur[s] over several calls." Early calls are reconnaissance to learn what a reset requires. By the time the real request arrives, the caller may know the process better than a new agent. A predictable check can be practised.

Your vendor's desk is your desk

Caesars named an outsourced IT support vendor. M&S named a third party. If a contractor can reset your staff's passwords, your verification standard is only as strong as that contractor's busiest shift. The UK's NCSC published guidance on 4 May 2025, during the retail attacks. It asks organisations to "review helpdesk password reset processes," especially for staff "with escalated privileges."

What Scam Atlas shows

Scam Atlas is a sourced library of scam types and real cases on this site. Each type page explains how an attack works, its red flags, what to do if targeted, and the controls that stop it. Each case page gives a timeline, the loss where one was disclosed, the legal status and the lessons.

The sourcing rules are strict. Under the Scam Atlas methodology, every case needs a Tier A source: a court record, regulator, law enforcement agency, SEC filing or the organisation's own disclosure. News reports count only as Tier B support. A case backed only by news is labelled "Unconfirmed by a primary source." People are named only as the primary source names them, and a charged person stays "charged" until a court says otherwise.

The workforce social engineering family holds ten attack types aimed at employees and help desks. They include MFA fatigue, fake IT support after email bombing, SIM swap and vishing into connected apps. At the time of writing, the family links to 18 real cases.

Finding 1: seven help desk cases, one clear court record

The help desk reset impersonation page links seven cases, from Twitter in 2020 to the 2025 US charges. Only TfL gives a recent court finding on how entry happened. At MGM the help desk detail rests on the attackers' claim, and Co-op has not published its entry point. Training material should keep those differences.

Finding 2: two of the seven went through someone else's desk

The Caesars case names an outsourced IT support vendor. The M&S case names a third party. For many organisations the weakest reset path is not their own staff. It is a contract nobody has tested.

Finding 3: the disclosed costs are large and specific

The table below uses only figures the organisations or authorities published. It shows why a five-minute verification step is cheap.

CaseWhat the primary record says about entryDisclosed costStatus
MGM Resorts, 2023Not disclosed; help desk call claimed by attackersAbout $100 million to Adjusted Property EBITDARDisclosed
Caesars, 2023Social engineering of an outsourced IT support vendorNot quantified in the 8-KDisclosed
Transport for London, 2024Helpdesk worker reset a password, as heard in court£29 million, reportedSentenced
Marks & Spencer, 2025Impersonation involving a third partyAbout £300 million of operating profit, estimatedDisclosed

How to use it: a walkthrough for IT teams

A help desk lead can turn Scam Atlas into training and process in this order.

  1. Start at the workforce scams hub. It lists every attack aimed at employees, help desks and finance teams on one page.
  2. Turn the help desk type page into your agent script. Its red flags are ready-made escalation triggers: a password reset and a new MFA device in the same call, identity proven only with researchable details, a privileged account, and pressure to hurry.
  3. Teach with the TfL timeline. It runs from the August 2024 intrusion to the July 2026 sentences. It shows new agents that one reset can take down more than 140 systems.
  4. Use Caesars and M&S for vendor reviews. Bring both case pages to your next outsourced service desk review, and ask the vendor to walk through a reset live.
  5. Check the legal status before you quote a case. The US charges page is marked "charged" and kept separate from the UK sentence. Keep that distinction in any internal briefing.
  6. Cover the neighbouring attacks. The same family page covers MFA fatigue and SIM swap, which is the same trick aimed at your mobile carrier's help desk. The guide SMS MFA is not MFA explains what to replace text codes with.

What to do next: a short reset checklist

The controls that hold share one property: an attacker cannot pass them with research or persistence. Mandiant's guidance calls for "a call-back to a registered number or confirmation via a known corporate email before proceeding with any sensitive request." It also lists on-camera, in-person and ID checks as positive identification methods.

  • Never act on the inbound call. Log the request, end the call and call back on the number held in HR or the directory.
  • Reject researchable proofs. Date of birth, Social Security digits, employee ID and manager's name do not count.
  • Split the request. A password reset plus a new MFA device in one ticket triggers escalation.
  • Verify privileged users on camera against the HR photo, with ID shown, before any admin reset.
  • Notify the user through a separate channel the moment any factor changes, and revoke existing sessions after a reset.
  • Put the same rules in every vendor contract, and test them with a call.
  • Move staff to phishing-resistant MFA. CISA's AA23-320A says to "require phishing-resistant multifactor authentication (MFA) for all services to the extent possible."

A second approver for high-risk changes

None of the primary sources in this post mandates manager approval by name, so treat this as my recommendation rather than published guidance. For administrator accounts, require a second person to approve the ticket inside an authenticated workflow. An approval sent by email or chat is only as strong as the mailbox it came from, and that mailbox may be the one under attack.

Protect the agent who says no

Tell agents in writing that delaying a real executive by ten minutes will never be held against them. A checklist only works if the person holding it feels safe using it under pressure. Then revisit the help desk type page each quarter and refresh the training when a new case appears.

Verification can still fail, so detection is the backstop. A reset followed within an hour by a new device, a bulk download or admin activity should alert your security team. The ITDR solutions comparison covers tools that watch for this. My earlier piece on how the phone line became the front door covers the voice channel more broadly.

Frequently Asked Questions

How do attackers bypass MFA through the help desk?

They call the IT help desk pretending to be an employee and ask for a password reset and a new MFA device. If the agent agrees, the attacker registers their own factor and signs in normally. CISA's advisory AA23-320A documents Scattered Spider using this method.

How should a help desk verify a caller before a password reset?

End the call and call the employee back on the number held in HR or the directory. For privileged accounts, add an on-camera check against the HR photo with ID shown. Mandiant warns never to rely on date of birth or Social Security digits, because attackers often hold them.

How did Scattered Spider get into MGM Resorts?

MGM has not said publicly how the attackers got in. Scattered Spider claimed, as TechCrunch reported, that it found an employee on LinkedIn and called the help desk. MGM's 8-K estimated about $100 million of impact to Adjusted Property EBITDAR.

What happened in the Transport for London cyber attack case?

Attackers accessed TfL's network between 31 August and 3 September 2024, reportedly after a helpdesk worker was tricked into a password reset. Thalha Jubair and a co-defendant who was a minor at the time pleaded guilty. Each was sentenced in July 2026 to five years and six months.

What is Scam Atlas and how does it grade cases?

Scam Atlas is a library of scam types and real cases on guptadeepak.com. Every case needs a primary source such as a court record, regulator, police statement or company filing. Cases backed only by news are labelled "Unconfirmed by a primary source."

Get new Scams & Cybersecurity writing

Enjoyed this? Subscribe and tell us what you read most. Scams & Cybersecurity is already ticked for you. No tracking pixels, unsubscribe with one click.

Tell us what you read most (optional)

About DeepakPublicationsAnalysisAll tracks