Gaming

The attack usually starts with a phone call, not a firewall

Gaming and entertainment operators are high value, highly visible targets, and the people attacking them have moved on from technical exploits to simply calling your staff and sounding convincing.

What actually happened

MGM Resorts lost around 100 million dollars after one phone call

In September 2023 attackers found an MGM Resorts employee on LinkedIn, phoned the IT help desk pretending to be them, and talked their way into a password reset. The resulting attack disrupted operations across more than thirty properties, and MGM reported roughly 100 million US dollars of impact in that quarter.

Source: MGM Resorts quarterly filing and reporting

What it means for you

No technology was defeated. A help desk process was, and that is a process you can fix this month.

What we hear

The pressure points in gaming

Help desk social engineering

Convincing phone calls asking for password resets and MFA changes, which is now the standard way in.

High value accounts

Staff, player, and publisher accounts worth real money to whoever takes them.

Uptime in public view

Outages that customers and press notice within minutes.

Content and pre release material

Unreleased work that leaks badly and permanently if it gets out.

What we put in place

Built for how you actually operate

Not a generic support plan with your industry written on the cover. These are the things that matter in your environment.

A help desk that cannot be talked past

Verified identity checks before any password or MFA reset, with the steps written down and followed every time.

Phishing resistant authentication

Stronger multi factor methods on the accounts that matter, so a stolen code is not enough.

Privileged access controls

Administrative rights granted narrowly and reviewed, so one compromised account does not reach everything.

24/7 SOC monitoring

Watching for the unusual sign ins and privilege changes that precede these attacks by days.

Content protection

Access controls and monitoring around pre release material and the people who handle it.

Recovery planning

Tested recovery for the systems that would take the business offline, planned before you need it.

What changes

What it looks like once this is running

We start by reviewing what you have now and telling you honestly what would cause problems. No obligation, and no pressure either way.

Talk about your environment
  • A help desk process an attacker cannot talk their way through
  • Administrative access that is narrow and reviewed
  • Early warning on unusual account activity
  • A tested way back from a serious incident

Let us look at your setup

A short call, a clear picture of where you stand, and a straight answer about what is worth fixing first.