Cybersecurity Isn’t Luck. Ask These Four Companies.

Cybersecurity Isn’t Luck. Ask These Four Companies.

Every one of these companies had a security budget, a security team, and a reason to think they were covered. None of it mattered once someone talked their way past the front door. Cybercrime isn’t a random storm that happens to land on unlucky targets — it’s a deliberate attempt to find the weakest human or the weakest password, and it usually finds one.

Here are four recent breaches that show how often that weak point is something as ordinary as an unverified phone call or a login with no second factor, not a sophisticated piece of malware.

MGM Resorts (September 2023). Attackers found an MGM employee’s profile on LinkedIn, called the company’s IT help desk pretending to be that employee, and talked their way into a password reset. Ten minutes on the phone was enough to gain administrator access to MGM’s systems. Slot machines, hotel key cards, and reservations went down for days. The bill: over $100 million. TechCrunch covered the fallout.

Clorox (August 2023). The same tactic hit Clorox weeks earlier, through its outsourced IT help desk. Attackers called in, claimed to be locked-out employees, and were handed working passwords without any real identity check. The resulting outage knocked out order processing for months and cost an estimated $380 million. CSO Online has the details.

Change Healthcare (February 2024). One stolen password got attackers into a remote access portal that had no multi-factor authentication turned on. From there they moved through the network undetected for nine days before deploying ransomware. The breach disrupted prescription and billing systems across U.S. healthcare and eventually touched close to 193 million people’s records. BleepingComputer broke down how it happened.

The Snowflake customer breach (2024). Attackers didn’t break into Snowflake itself — they reused old employee login credentials that had leaked from separate malware infections years earlier and were never changed. Because the affected customer accounts also had no MFA enabled, those stale passwords still worked. AT&T, Ticketmaster, and more than a hundred other companies were hit. Wikipedia has a well-sourced rundown of the timeline.

Four different industries, four different attackers, and the same pattern each time: a password that should have expired, or a help desk that skipped a verification step. None of these companies were unlucky. They were targeted, and the door happened to be unlocked.

For a small or mid-sized business, the fix isn’t complicated, even if it takes discipline to keep up: multi-factor authentication on everything that touches sensitive data, a help desk (in-house or outsourced) that verifies identity before ever resetting a password, and old credentials that actually get retired instead of quietly staying valid. That’s the same groundwork we build into every client environment — it’s a lot cheaper than cleaning up after a breach.