Have any questions? +1 646.844.5712 (US)

  • Facebook
  • LinkedIn
  • Twitter
HiTech ServiceHiTech Service
  • Home
  • About
  • Services
    • Software Development
    • Customer Support
    • Quality Assurance
    • Managed Services
    • Compliance Audit
    • GDPR Compliance
    • Competency Center
    • Emergency IT Support
    • Software as medical device
    • Local AI Agent Development
  • Projects
  • GDPR
  • Articles
  • Case Studies
  • Contact
Menu
  • Home
  • About
  • Services
    • Software Development
    • Customer Support
    • Quality Assurance
    • Managed Services
    • Compliance Audit
    • GDPR Compliance
    • Competency Center
    • Emergency IT Support
    • Software as medical device
    • Local AI Agent Development
  • Projects
  • GDPR
  • Articles
  • Case Studies
  • Contact
A phone headset icon connected by a glowing red line straight through an open unlocked shield icon into a server vault, symbolizing a security bypass through conversation rather than a technical exploit

A 10-Minute Phone Call Took Down MGM’s Systems. The 19-Year-Old Behind a Similar Scheme Just Got Extradited.

By Alex

Peter Stokes is 19 years old, holds dual US and Estonian citizenship, and was arrested in Finland this past April on an Interpol Red Notice. He was extradited to the United States and made his first federal court appearance in Chicago, charged with conspiracy, cyber intrusion, and fraud. Prosecutors allege he’s a member of Scattered Spider — a hacking collective tied to more than 100 network intrusions, over $100 million in ransom payments, and a body of technique that has almost nothing to do with sophisticated malware and almost everything to do with a convincing phone call.

The specific case against Stokes involves a luxury jewelry retailer, breached and held for an $8 million cryptocurrency ransom demand in May 2025. The retailer’s security team evicted the attackers and refused to pay — a genuine defensive win — and still ended up out at least $2 million in business disruption, investigation, and cleanup costs. That gap, between “we didn’t pay the ransom” and “we still lost millions,” is the part worth sitting with before getting to how these attacks actually work.

The Method: No Exploit Required

A profile card with a magnifying glass over it, connected to a phone headset icon, connected to a help desk counter with an agent, representing reconnaissance leading into a vishing call

Scattered Spider’s signature technique, most visibly demonstrated in the 2023 MGM Resorts breach, doesn’t involve a software vulnerability at all. Attackers used LinkedIn to identify a real MGM employee, then called the company’s IT help desk impersonating that person. The call lasted ten minutes. By the end of it, the caller had convinced a help desk technician to reset credentials and hand over enough access to reach administrator privileges inside MGM’s Okta and Azure tenant environments — the identity and cloud infrastructure controlling access to practically everything else.

No phishing email had to be clicked. No malware had to execute. The entire attack surface was a help desk employee’s judgment call about whether the person on the phone was who they claimed to be, under time pressure, sounding plausible, with just enough real personal detail (gathered beforehand from social media and public business directories) to pass a casual identity check.

The group runs this as a repeatable process, not an improvised trick: open-source reconnaissance across social media and B2B platforms to build a convincing identity profile, layered phone calls to learn an organization’s specific password-reset procedures, and then a final spearphishing call — often to the help desk directly — engineered to get a password reset or an MFA token transferred to a device the attacker controls. At Caesars Entertainment, the group took a related but distinct path in, compromising a third-party IT support vendor rather than calling Caesars directly, stealing loyalty-program data, and prompting Caesars to pay a $15 million ransom rather than risk a broader leak.

Why This Keeps Working

A help desk agent silhouette being pulled between a glowing red stopwatch arrow representing speed pressure and a teal shield-checkmark arrow representing verification requirements

None of these techniques are secret. CISA has published advisories on Scattered Spider’s methods since 2023. The MGM and Caesars breaches were extensively covered, picked apart in postmortems, and used as case studies in security training programs industry-wide. And the group’s next reported victim, per the Stokes complaint, still lost $2 million in May 2025 — two years after the technique became public knowledge.

That persistence points to something less fixable than a single patch or awareness campaign: identity verification at a help desk is fundamentally a human judgment problem, layered on top of a structural incentive problem. Help desk staff are measured and often compensated on resolution speed and caller satisfaction, not on how many legitimate callers they inconvenienced by insisting on rigorous verification. An attacker exploiting that dynamic isn’t finding a bug in the software — they’re finding the gap between “verify this caller’s identity thoroughly” and “resolve this ticket quickly,” and organizations that don’t explicitly resolve that tension in favor of verification keep landing in exactly this spot.

What Actually Closes the Gap

The defensive lesson from four-plus years of Scattered Spider incidents isn’t a firewall rule or an endpoint detection product — it’s identity verification procedure that doesn’t rely on the help desk employee’s on-the-spot judgment at all. Callback verification to a number already on file rather than one the caller provides, mandatory in-person or video identity checks for privileged account resets, and removing help desk agents’ ability to unilaterally reset MFA for high-privilege accounts without a second approval all directly target the exact step in the process that worked against MGM, and that Stokes is now accused of using against a jewelry retailer two years later.

Extraditing one 19-year-old doesn’t retire a technique that keeps succeeding regardless of who’s executing it. The jewelry retailer in the Stokes case did the technically right thing — refused to pay, evicted the attackers — and still absorbed a seven-figure loss. The organizations that avoid becoming the next case study are the ones that closed the actual gap Scattered Spider exploits, not the ones waiting for the next arrest to feel like closure.

  • On June 23, 2026
  • 0 Comment
Tags: cybersecurity, data breach, Scattered Spider, social engineering

Leave Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts
  • Why Load Test Numbers Lie
  • When Config Became Executable: The Twenty-Year Pattern Behind Supply Chain Attacks
  • How Software Became a Medical Device
  • Compliant With What? A Working Map of GDPR, HIPAA, SOC 2 and ISO 27001
  • Local AI vs Cloud AI: The Break-Even Is About Utilization, Not Tokens
Categories
  • ai (7)
  • android (18)
  • apple (36)
  • chart (18)
  • cloud (1)
  • fix (42)
  • games (11)
  • google (31)
  • hardware (73)
  • healthcare (3)
  • how to (231)
  • internet (92)
  • ios (23)
  • macos (3)
  • microsoft (82)
  • mobile (36)
  • news (74)
  • optimization (17)
  • osx (4)
  • outsourcing (8)
  • qa (3)
  • regulation (7)
  • review (120)
  • security (37)
  • software (159)
  • windows (150)
Archives
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • August 2025
  • March 2025
  • February 2025
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • March 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018
  • November 2018
  • October 2018
  • September 2018
  • June 2018
  • May 2018
  • April 2018
  • February 2018
  • January 2018
  • December 2017
  • November 2017
  • October 2017
  • June 2017
  • May 2017
  • April 2017
  • March 2017
  • February 2017
  • January 2017
  • December 2016
  • November 2016
  • October 2016
  • September 2016
  • August 2016
  • July 2016
  • June 2016
  • May 2016
  • April 2016
  • March 2016
  • February 2016
  • January 2016
  • December 2015
  • November 2015
  • October 2015
  • September 2015
  • July 2015
  • January 2015
Archives
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • August 2025
  • March 2025
  • February 2025
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • March 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018
  • November 2018
  • October 2018
  • September 2018
  • June 2018
  • May 2018
  • April 2018
  • February 2018
  • January 2018
  • December 2017
  • November 2017
  • October 2017
  • June 2017
  • May 2017
  • April 2017
  • March 2017
  • February 2017
  • January 2017
  • December 2016
  • November 2016
  • October 2016
  • September 2016
  • August 2016
  • July 2016
  • June 2016
  • May 2016
  • April 2016
  • March 2016
  • February 2016
  • January 2016
  • December 2015
  • November 2015
  • October 2015
  • September 2015
  • July 2015
  • January 2015

OpenAI Wants to Give the US Government a 5% Stake. The Pitch Compares It to Alaska's Oil Fund — But AI Isn't Oil.

Previous thumb

Broadcom Is Worth More Than Tesla and Meta Combined-Adjacent — and Almost Nobody Outside Finance Has Noticed

Next thumb
Scroll

Services

  • Software Development
  • Quality Assurance
  • Customer Support
  • Managed Services
  • 24/7 Emergency IT Support
  • Competency Center
  • Local AI Agent Development
  • Software as a Medical Device

Compliance

  • Compliance Audit
  • GDPR Compliance
  • What is GDPR
  • ISO 9001:2015 Certification

Company

  • About Us
  • All Services
  • Projects
  • Case Studies
  • Articles
  • Contact
About HiTech Service

With 10 year experience of working together, we have reached tangible synergetic effect in performance and productivity, which results in highest quality services and satisfied clients.

Privacy Policy   Cookie Policy

 

  • Facebook
  • X
  • LinkedIn
CONTACT INFO
  • 900 Foulk Rd, Suite 201, Wilmington, DE, USA, 19803
  • Kudryavs’kyi descent 5b, Kyiv, Ukraine, 04053
  • +1 646.844.5712 (US)
ISO 9001:2015 certificate issued to HiTech Service LLC by Veritas
RIPE Atlas logo, the network measurement community HiTech Service takes part in
BrainBasket Foundation logo, IT education initiative HiTech Service supports
HiTech Service LLC membership badge of the Hi-Tech Office Ukraine association Dun & Bradstreet verified business badge for HiTech Service LLC
YouTeam partner badge for HiTech Service LLC
Hitech Service LLC

Copyright 2026