Early September 2023, two of the world’s largest casino hotel companies — MGM Resorts and Caesars — were struck by ransomware attacks. In the week after, Caesars stated that the company had been a victim of “a social engineering attack on an outsourced IT support vendor used by the Company.” The hackers exploited a weak point in these companies’ security, underscoring the urgency of readdressing and improving our approach to online security.
Fallback Vulnerabilities
To gain access to sensitive data, hackers exploited these Okta users’ fallback method: the account reset or recovery process for when a user forgets their password or can’t log in with their usual multi-factor authentication (MFA).
Following these attacks, Okta warned its customers against a new pattern of social engineering in which a hacker may convince IT to reset MFA settings for user accounts. Caesars also admitted that their data was compromised because an IT personnel was tricked into resetting or redirecting an administrator’s account’s MFA. In this case, the fallback method was the weak link in the company’s security.
Cybersecurity companies have been working to address security issues, especially those related to the fallback process. However, it’s time to stop patching an old ship and move on to something more secure using technology that’s ready and available today.
Two Independent Endpoints
The cybersecurity world has made the mistake of tying your accounts to your phone: you can’t access online apps and services on any computer without first verifying yourself on your phone. This co-dependency is the point of weakness in the fallback process.
The better solution is to have two independent endpoints: the computer and the phone. With your endpoints working independently, each device can deliver secure user verification without the other. The computer can access online apps and services without the phone and the phone can access these services without a secondary device.
When There’s Nothing for Attackers to Phish
The endpoint is directly capable of verifying the user. By freeing the endpoint to act as the primary authentication device, we can achieve a no-user-action experience.
If service providers verified the endpoint and the user instead of only the user, users wouldn’t be required to do extra authentication steps, such as accepting push notifications, on a secondary device. In this setup, the user doesn’t authenticate to online accounts — they authenticate to the endpoint and the endpoint authenticates to online accounts. Therefore, there’s nothing for attackers to phish because the user doesn’t perform any online authentication acts.
Also, the more complex the user authentication steps are, the more likely it is for the user to make a mistake. By removing authentication steps, users can’t make mistakes for cybercriminals to exploit. This concept is similar to what occurred with the Caesars and MGM attacks except, in these cases, a Help Desk employee was fooled instead of the user. Your entire security structure can benefit from simplifying your authentication processes.
Reduce Your Fallback Rate
By allowing your computer to perform user authentication and creating a no-user-action experience, you significantly reduce the risk of needing a fallback method at all. Consider this: for the Caesars and MGM attacks, the hacker, posing as a legitimate user, pretended their MFA was faulty and requested a reset. Removing MFA steps from online authentication works removes this weak point the hackers exploited.
A Stronger Fallback Process
The endpoint accessing the online services should be able to act independently from your secondary device. For example, the computer should be able to access your Dropbox account without you having to enter an OTP on your phone.
If, for some reason, your main authentication doesn’t work, we can use the phone as a fallback authentication factor. In this case, the fallback method is the phone, which is what most authentication providers are using for their primary method. Relying on the computer endpoint for authentication is so strong and secure that the phone becomes the secondary line of defense.

Futureproof Your Data
The Caesars and MGM attacks have demonstrated once again what industry insiders already know: user authentication must be phishing-resistant and mainstream fallback methods can be vulnerable to cyber-attacks. Businesses are now reassessing their entire security system from login to the fallback process.
The bottom line is that your endpoints should be able to work independently without needing the other: the computer should be able to access online apps and services without the phone and vice versa. One of these endpoints can work as a secondary device to verify the user, offering a reset or recovery process that’s more secure than other fallback methods.
It’s time to move beyond “good enough” and accept there’s a better option that doesn’t leave your back door open. WinMagic’s MagicEndpoint passwordless solution delivers no-user-action authentication that keeps all verification works out of hackers’ hands. By focusing on the endpoint, your IT won’t have to deal with password resets or MFA failures, cutting off that avenue so hackers can’t exploit it.
The technology is out there — you just have to reach for it.
Want to see for yourself? Schedule a demo to see MagicEndpoint in action.




