Skip to content

Part III: Slot Machine Cheating · Electronic & Digital Cheating Methods

SCAM #19: Help Desk Vishing (Voice Phishing) Attack

Social EngineeringSkill: Intermediate

How it works

Attackers research casino employees on LinkedIn and other social media to gather information about their roles, responsibilities, and relationships. They then call the casino IT help desk posing as the employee, using the gathered information to establish credibility. The attacker claims to be locked out of their account or having technical difficulties and persuades the help desk to reset passwords, disable multi-factor authentication, or provide new credentials. Once credentials are obtained, the attackers gain access to internal systems and can move laterally through the network, eventually reaching gaming systems. Scattered Spider perfected this technique — their members are fluent English speakers who research their targets thoroughly before calling. Modern variants may use AI-generated voice synthesis to perfectly impersonate the target employee’s voice using just a few seconds of audio from public sources.

Where it appears

Casino IT infrastructure, eventually leading to gaming systems, CMS, player databases, and financial systems

On the record

The MGM Resorts September 2023 attack began with a 10-minute phone call to the IT help desk in which attackers, impersonating an employee found on LinkedIn, obtained credentials that led to administrator privileges over MGM’s Okta and Azure environments. The same group, Scattered Spider, had successfully used similar tactics against telecommunications and technology companies before targeting casinos.

Published as a detection reference for surveillance, compliance and gaming-operations professionals. Thresholds and tuning are set by the property. Nothing here is instruction — the method is described so it can be recognised.

Related methods