Close Menu
    Facebook X (Twitter) Instagram
    Trending
    • Smishing 101: Stop Text-Message Scams Before They Start
    • Teen Helps in Extorting Casino for a Hundred Million Dollars Through Cyberattacks: What Can You Do to Help Keep Yourself Safe Online?
    • Akira Ransomware Group Exploits SonicWall VPNs
    • How to Help Grandparents Spot AI-Driven Misinformation
    • What is CASB by Proofpoint?
    • The Parallels of Pirating and AI in the Entertainment Industry
    • Stealerium: When Malware Crosses the Line Into Sextortion
    • MFA Bypass Attacks: What You Need to Know
    Fordham University Information Security and Assurance
    • Information Security and Assurance Homepage
    • Privacy Blog
    • About
    Fordham University Information Security and Assurance
    You are at:Home»Cyber Security Awareness Month Tip»Teen Helps in Extorting Casino for a Hundred Million Dollars Through Cyberattacks: What Can You Do to Help Keep Yourself Safe Online?
    Cyber Security Awareness Month Tip

    Teen Helps in Extorting Casino for a Hundred Million Dollars Through Cyberattacks: What Can You Do to Help Keep Yourself Safe Online?

    By Kevin DjakaOctober 8, 2025Updated:October 8, 20253 Mins Read
    Hacker trying to gain information while sitting on rails.
    Share
    Facebook Twitter LinkedIn Pinterest Copy Link

    Do you recall what you were doing at age 15?

    I would not be surprised if you said trying out new activities, clubs, relaxing, or working. A teenager, only 15 years old at the time, allegedly took working to a different level, contributing to a casino operator losing around $100 million through a series of cyberattacks. 

    Cyberattacks are Indifferent

    When most people think of cyberattacks, they imagine complex campaigns from faraway groups. That is not the full picture. Cyberattacks are indifferent to who you are and where you are. Consider this: a 15-year-old boy, now 17, has been accused of helping attack one of the largest casino operators in the world, MGM Resorts International.

    The teenager allegedly helped cause havoc in a multibillion-dollar industry using voice phishing and service-desk social engineering. Instead of dropping malware first, attackers won trust, phoned the help desk, and reset passwords after identifying staff through LinkedIn.

    You might ask yourself, “How did no one catch the problem beforehand?”

    The Speedy Rise of Voice Phishing

    It is not easy to catch this kind of problem in real time. While defenses vary, vishing has improved fast. Today, one convincing call to IT support can be enough to start privilege escalation and move inside identity platforms. That is exactly why recent analyses of the MGM incident focus on the initial help-desk social engineering and weak verification at the service desk.

    The media focused on the age of the suspects because it is surprising, but do not miss the technique: find an employee on LinkedIn, impersonate them credibly, then push for a reset or session hijack. It is social engineering, not magic.

    While this incident occurred on a large scale, that doesn’t mean something of a small scale can’t happen to you. Make sure you keep yourself safe!

    How to Keep Yourself Safe

    1. Remove or disable apps you do not use. Fewer apps mean fewer outdated permissions and fewer targets.
    2. Store passwords in a trusted password manager, not phone notes or paper. If one login is stolen, a manager makes unique passwords practical, and one breach will not open everything else.
    3. Back up important data in two places, for example, one external drive and one reputable cloud service. Test restore occasionally so you know backups work.
    4. Use WPA3 on home Wi-Fi if your router supports it, and change the default admin credentials.
    5. Turn on multifactor authentication for email, banking, and any account that touches money or identity.
    6. Teach a help-desk password-reset rule for your family or small business: no changes on voice alone; require a known out-of-band check, such as an app prompt or a code sent to a pre-registered number. (This directly counters the MGM-style playbook.)

    Sources

    • ‘Sophisticated’ $100M cyberattack on Vegas Strip involved teen hacker: police
    • MGM Resorts hack: How attackers hit the jackpot with service desk social engineering
    • Cloud Storage vs External Hard Drive: Advantages & Disadvantages in 2025

     

     

    cyberattacks Cybersecurity Awareness Month Tip hackers
    Previous ArticleAkira Ransomware Group Exploits SonicWall VPNs
    Next Article Smishing 101: Stop Text-Message Scams Before They Start

    Related Posts

    Smishing 101: Stop Text-Message Scams Before They Start

    Akira Ransomware Group Exploits SonicWall VPNs

    How to Help Grandparents Spot AI-Driven Misinformation

    Follow Us on Twitter!
    Follow @FordhamSecureIT
    My Tweets
    Archives
    Categories
    • AI (1)
    • Alerts (384)
    • CISO (20)
    • Cyber Security Awareness Month Tip (154)
    • Data Privacy Week (2)
    • Executive Director (1)
    • Exploits and Vulnerabilities (35)
    • General Information (35)
    • Identity and Access Management (12)
    • Identity Theft (26)
    • Jason Benedict (20)
    • Legitimate Email (14)
    • Malicious Email (24)
    • Mobile (25)
    • Network Security (3)
    • News and Events (144)
    • Newsletter (13)
    • Password (18)
    • Phishing (336)
    • Phishing Email (340)
    • Privacy (10)
    • Ransomware (10)
    • Scam (107)
    • Security Awareness (269)
    • Security Guides (35)
    • Social Engineering (13)
    • SPAM (40)
    • Suspicious (6)
    • Telework (2)
    • Teleworking (3)
    • Trojan (7)
    • Uncategorized (9)
    • Virtual Meeting (4)
    • Virus (29)
    • Viruses (8)
    • World Backup Day (1)
    • Zoom (6)
    Tag Cloud
    Alerts Artificial Intelligence Backups cell phones CISO crowdstrike Cybersecurity Awareness Month Tip Cybersecurity Month Data Privacy Device email Exploits and Vulnerabilities firewalls fraud Identity and Access Management Identity Theft Information Security Guides Jason Benedict Legitimate Email malicious email Mobile Multi-Factor Authentication networks Network Security News and Events Newsletter online safety Online Shopping Password Phishing Phishing Email Privacy ransomware scam Security Awareness social engineering Social Media spam trojan Virus Viruses Wireless wire transfer scam World Backup Day zoom
    About
    About

    Founded in 1841, Fordham is the Jesuit University of New York, offering exceptional education distinguished by the Jesuit tradition to more than 15,100 students in its four undergraduate colleges and its six graduate and professional schools.

    Copyright © Fordham University
    Facebook X (Twitter) Instagram YouTube LinkedIn
    © 2025 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.