Securing helpdesks from hackers: What we can learn from the MGM breach

In the wake of the MGM Resorts service desk hack, it's clear that organizations need to rethink their approach to security, particularly when it comes to verifying the identity of employees contacting the helpdesk.
In this article, we'll explore how you can prevent such incidents in your organization and ensure that your helpdesk is a stronghold of security.
Before we dive into prevention strategies, let's briefly recap the MGM Resorts service desk hack.
They meticulously researched and impersonated an MGM Resorts employee using information gathered from LinkedIn, creating a convincing facade to deceive the helpdesk staff.
This initial breach was facilitated by the absence of a robust end-user verification system at the service desk, allowing the attackers to bypass security measures and gain unauthorized access.
Helpdesk staff are on the frontline when it comes to security.
Particularly those targeting helpdesk personnel, are meticulously crafted to manipulate human psychology.
Helpdesk staff, in their role to provide prompt and efficient service, may inadvertently become more susceptible to these manipulative strategies.
The nature of helpdesk work, which emphasizes rapid response and problem-solving, can sometimes lead to a compromise in security protocols.
To fortify your organization's helpdesk against potential cyber threats, you need a holistic strategy that integrates technological solutions and addresses human factors.
While helpdesk staff are generally aware of basic cybersecurity risks, it's crucial to provide ongoing training to brief them on new and emerging forms of attacks.
Emphasize the importance of rigorous user identity verification to maintain a robust security posture.
Shift towards a more secure verification process for Active Directory users by adopting solutions like Specops Secure Service Desk.
Secure Service Desk can help enforce verification of higher risk requests like account lockouts and password resets.
Regularly audit your helpdesk and user verification processes to identify and mitigate potential vulnerabilities.
Employ penetration testing to simulate social engineering attacks and assess the resilience of your helpdesk staff and security protocols.
The MGM Resorts service desk hack serves as a stark reminder of the importance of secure verification processes at the helpdesk level.
Specops Secure Service Desk ensures a stringent verification process for all Active Directory users, confirming their status as authorized employees prior to initiating any password resets or account unlocks.
This system fortifies your helpdesk's security protocols, removing insecurities or manual verification methods.
Take the first step towards a more secure helpdesk and protect your organization's sensitive information - contact Specops today to implement Secure Service Desk in your environment.


This Cyber News was published on www.bleepingcomputer.com. Publication date: Mon, 08 Jan 2024 15:50:37 +0000


Cyber News related to Securing helpdesks from hackers: What we can learn from the MGM breach

Data Breach Response: A Step-by-Step Guide - In today's interconnected world, organizations must be prepared to respond swiftly and effectively in the face of a data breach. To navigate these challenges, a well-defined and comprehensive data breach response plan is essential. Let's explore the ...
4 months ago Securityzap.com
Tech Security Year in Review - In this Tech Security Year in Review for 2023, let's look into the top data breaches of the past year. Each factor contributes to the growing threatscape, demanding a proactive and adaptable cybersecurity approach to safeguard your organization ...
6 months ago Securityboulevard.com
Securing helpdesks from hackers: What we can learn from the MGM breach - In the wake of the MGM Resorts service desk hack, it's clear that organizations need to rethink their approach to security, particularly when it comes to verifying the identity of employees contacting the helpdesk. In this article, we'll explore how ...
5 months ago Bleepingcomputer.com
Securing Student Data in Cloud Services - In today's educational landscape, securing student data in cloud services is of utmost importance. One key aspect of securing student data in cloud services is ensuring proper data encryption. This article explores the various challenges and best ...
6 months ago Securityzap.com
How Can Data Breach Be A Trouble For Your Industry? - To navigate an era of cyber risks, this unsettling reality necessitates a renewed focus on data integrity protection and digital asset protection. In this blog, we will discuss a data breach in the Hospitality industry. Some of the companies like MGM ...
6 months ago Securityboulevard.com
5 Valuable Skills Kids Can Gain by Playing Video Games - Video games come in all shapes and sizes and can be very educational for children of all ages. Video games can provide children with valuable skills that can help them in their everyday lives. From problem-solving abilities to self-control, learning ...
1 year ago Welivesecurity.com
PennyMac Files Notice of Data Breach That Leaked Thousands of SSNs - On October 19, 2023, PennyMac Loan Services LLC filed a notice of data breach with the Attorney General of Texas after discovering that unauthorized actors were able to access information that had been entrusted to the company. In this notice, ...
7 months ago Jdsupra.com
Welltok Data Breach: 8.5M US Patients' Information Exposed - In a recent cybersecurity incident, Welltok, a leading healthcare Software as a Service provider, reported unauthorized access to its MOVEit Transfer server, affecting the personal information of approximately 8.5 million patients in the United ...
6 months ago Securityboulevard.com
Toronto Zoo: Ransomware attack had no impact on animal wellbeing - Toronto Zoo, the largest zoo in Canada, says that a ransomware attack that hit its systems on early Friday had no impact on the animals, its website, or its day-to-day operations. The zoo said it doesn't store any credit card information and is also ...
5 months ago Bleepingcomputer.com
HPE investigates new breach after data for sale on hacking forum - Hewlett Packard Enterprise is investigating a potential new breach after a threat actor put allegedly stolen data up for sale on a hacking forum, claiming it contains HPE credentials and other sensitive information. The company has told ...
4 months ago Bleepingcomputer.com
Ex-Uber CSO: Lessons Learned from the Breach and Legal Case - BLACK HAT EUROPE 2023 - London - Former Uber CISO Joe Sullivan last week shared new details about the 2016 data breach at the company that led to his firing from Uber and, later, felony charges. The Uber Breach Sullivan was in his second year as CISO ...
6 months ago Darkreading.com
Welltok data breach exposes data of 8.5 million US patients - Healthcare SaaS provider Welltok is warning that a data breach exposed the personal data of nearly 8.5 million patients in the U.S. after a file transfer program used by the company was hacked in a data theft attack. Welltok works with health service ...
7 months ago Bleepingcomputer.com
Holiday Hackers: How to Safeguard Your Service Desk - Hackers really don't take holidays, but they will take advantage of them. Many of these cyberattacks will zero in on the service or help desk to gain entry into network systems. Recovering accounts because of forgotten passwords is one of the ...
6 months ago Bleepingcomputer.com
AvidXchange Notifies Consumers of Data Breach Following Period of Unauthorized Access - On October 13, 2023, AvidXchange, Inc. filed a notice of data breach with the Attorney General of Massachusetts after discovering that a recent cybersecurity event resulted in an unauthorized party being able to access the company's IT network. In ...
7 months ago Jdsupra.com
Akumin Files Notice of Data Breach with the Securities and Exchange Commission - On October 16, 2023, Akumin Inc. filed a notice of data breach with the Securities and Exchange Commission after discovering that it had been the recent victim of a ransomware attack. In this notice, Akumin explains that the incident resulted in an ...
7 months ago Jdsupra.com
Texas Retina Associates Notifies Nearly 300k People of Recent Data Breach - On June 26, 2024, Texas Retina Associates filed a notice of data breach with the Attorney General of Texas after discovering that confidential information that had been entrusted to the company was subject to unauthorized access. In this notice, ...
1 week ago Jdsupra.com
How Hackers Interrupted GTA 5 Online Gameplay on PC - Recently, a cyber-attack on Grand Theft Auto 5 Online on PC caused an interruption to thousands of players’ gameplays. The game was completely taken offline and players couldn’t even access the main gameplay menu. The attack caused an uproar ...
1 year ago Hackread.com
Keenan & Associates Reports Data Breach Exposing Social Security Numbers of More Than 1.5M - PRESS RELEASE. MARLTON, N.J., Jan. 29, 2024 /PRNewswire/ - Approximately 1.5 million consumers are being notified that their Social Security numbers and other confidential information were compromised when an unauthorized party was able to access the ...
5 months ago Darkreading.com
Goto Customers Backup Data Breach: Protect Your Business and Handle Data Breach Risks - A data breach at Goto customers exposed their backup data to malicious actors, leading to a data breach that impacted those customers. Businesses need to be aware of the risks associated with data breaches and how to protect their organisations from ...
1 year ago Securityaffairs.com
Fellowship Village Files Notice of Data Breach with the Federal Government - On October 8, 2023, Fellowship Village filed a notice of data breach with the U.S. Department of Health and Human Services Office for Civil Rights after discovering that there was unauthorized access to the company's computer network. In this notice, ...
7 months ago Jdsupra.com
Breach Ready: Fortifying Your Defenses in the Age of Cyberattacks - In today's highly digitalized and collaborative business environment, the likelihood of a cybersecurity breach is a matter of when, not if. Nearly every high-profile breach reported in the news has been a result of a cyberattack that penetrated ...
3 months ago Cybersecurity-insiders.com
Clear Spring Life and Annuity Company Announces Data Breach Following Ransomware Attack - On November 21, 2023, Clear Spring Life and Annuity Company filed a notice of data breach with the Attorney General of California after discovering a February 2023 ransomware attack. In this notice, Clear Spring explains that the incident resulted in ...
7 months ago Jdsupra.com
Prestige Care Announces Data Breach Affecting an Unknown Number of Residents and Employees - On November 6, 2023, Prestige Care Inc. filed a notice of data breach with the U.S. Department of Health and Human Services Office for Civil Rights after discovering that an unauthorized party accessed the company's computer network. In this notice, ...
7 months ago Jdsupra.com
Cardiovascular Consultants Confirms Data Breach in SEC Filing - On December 6, 2023, Cardiovascular Consultants Ltd. filed a notice with the Securities and Exchange Commission disclosing a recent cyberattack and subsequent data breach. In this notice, Cardiovascular Consultants explains that the incident resulted ...
6 months ago Jdsupra.com
Retool Data Breach Affects MG Stover and Multiple Investment Funds - On September 29, 2023, MG Stover filed a notice of data breach with the Attorney General of Massachusetts after discovering that Retool, one of the company's vendors, experienced a cybersecurity incident that exposed confidential information. In this ...
7 months ago Jdsupra.com

Latest Cyber News


Cyber Trends (last 7 days)


Trending Cyber News (last 7 days)