Skip to main content

Real-World Cybersecurity
Incidents

Walk through actual breaches step by step. Reconstruct each attack chain and identify the warning signs at every stage.

2 interactive case studies based on documented incidents. Free to play, no sign-up required.

Frequently Asked Questions

How do attackers use lookalike domains in BEC fraud?

Attackers register domains that differ by one or two characters from the target company, such as swapping "rn" for "m" or adding a hyphen.

After monitoring legitimate email chains, they inject themselves into invoice conversations using these near-identical domains. Recipients often miss the difference because the context, formatting, and timing all match real correspondence.

How did the MGM Resorts breach happen in 2023?

The Scattered Spider threat group called MGM's IT helpdesk, impersonated an employee using publicly available LinkedIn information, and convinced staff to reset credentials. That single 10-minute phone call gave attackers initial access.

They then deployed ALPHV/BlackCat ransomware, shutting down hotel systems, slot machines, and booking platforms. MGM reported over $100M in total impact.

What is Scattered Spider?

Scattered Spider is a financially motivated threat group known for social engineering attacks against large organizations. They specialize in helpdesk vishing, SIM swapping, and MFA fatigue attacks to gain initial access.

The group has targeted major hospitality, technology, and telecommunications companies, often partnering with ransomware-as-a-service operators like ALPHV/BlackCat for the encryption and extortion phase.

See RansomLeak in Action

Try the free exercises or book a demo to see analytics, SCORM export, SSO, and custom content in your environment.