Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft says Octo Tempest, a financially motivated hacking group linked in reporting to the 2023 Las Vegas casino attacks, used physical threats in rare instances to pressure selected victims into sharing corporate credentials. But the available evidence does not show that threats were used to break into MGM Resorts or Caesars Entertainment. The casino incidents were associated with social engineering, and Caesars disclosed access involving an outsourced IT support vendor.

What Microsoft found about physical threats

In an October 25, 2023 report, Microsoft Threat Intelligence and Microsoft Defender Experts Cybersecurity Incident Response described physical threats as a rare part of Octo Tempest’s broader extortion and social-engineering activity. Microsoft wrote: “In rare instances, Octo Tempest resorts to fear-mongering tactics, targeting specific individuals through phone calls and texts.”

The report says actors sometimes used personal information, including home addresses and family names, together with physical threats to coerce people into sharing corporate access credentials. Microsoft did not publish a count or percentage for these incidents, so “rare” is a qualitative description, not a measured rate. Microsoft’s October 2023 Octo Tempest report

Do the threats explain the MGM or Caesars breaches?

No public evidence cited in contemporaneous coverage establishes that violent threats were used to gain access to either casino company. Microsoft’s finding concerns the group’s campaigns more broadly; it should not be presented as the entry method for the Las Vegas incidents.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Caesars Entertainment

Caesars disclosed unauthorized access in September 2023 associated with an outsourced IT support vendor. The company said customer loyalty data may have included sensitive personal information. The Associated Press reported the disclosure at the time. Associated Press coverage of Caesars’ disclosure

MGM Resorts

MGM reported a cybersecurity incident and shut down systems as a protective measure. Contemporary reporting described disruption to reservations, payments, ATMs, room access and some casino services. Cybersecurity Dive’s September 14, 2023 report

Attribution details reported soon after the attacks included security researchers’ assessments and claims by alleged attackers; those are not equivalent to confirmed company disclosures. The Washington Post covered the attribution discussion and reported intrusion tactics in September 2023. The Washington Post’s coverage

How the group’s social engineering works

Microsoft describes a progression from SIM-swapping and account takeover toward enterprise social engineering, extortion and ransomware activity. Documented approaches include researching targets, impersonating employees, and persuading help-desk staff or technical administrators to reset passwords or multifactor authentication. These techniques can turn routine identity-support processes into an access route.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft’s later July 2025 research discusses activity across multiple industries and defensive posture; a joint government advisory issued July 29, 2025 uses the name Scattered Spider. Microsoft’s Octo Tempest naming overlaps with labels used by other researchers, including Scattered Spider, UNC3944 and 0ktapus. These names reflect different tracking practices and should not be treated as proof that every label describes an exactly identical organizational unit. Microsoft’s July 2025 report Joint Scattered Spider advisory

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What organizations can do about coercive help-desk attacks

Microsoft’s descriptions point to three useful areas for organizations to review. These are defensive practices, not evidence that any one control would have prevented the casino incidents.

  • Harden identity changes. Define how staff verify identity before resetting a password or MFA method. Where practical, confirm requests through a trusted, separate channel rather than relying on details supplied during the call or message.
  • Prepare staff for pressure tactics. Train help-desk and technical staff to recognize impersonation, unusual urgency, and coercive contact, and to escalate rather than bypass normal verification when a caller invokes threats.
  • Review account changes promptly. Ensure security teams can identify and investigate password or MFA changes that are unusual for the account, with an escalation path for reports of threats or suspected coercion.

Microsoft recommends ongoing user education and targeted awareness campaigns in its reporting. Microsoft’s October 2023 guidance

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.