The trick works like this:
A hacker "phishes" for login credentials by making a fraudulent phone call to a company's helpdesk, posing as an employee who cannot log into their account.
Often times the attacker makes their approach more convincing by gathering information in advance from social media about the individual they are impersonating.
Just such a trick was used against the MGM Resorts casinos in Las Vegas in 2023, which left guests unable to enter their rooms, ATM machines offline, and phone lines taken down.
MGM Resorts, which refused to pay a ransom to its extortionists, claimed that the attack cost its businesses over US $100 million.
Last year British police made an arrest related to the attack of a teenager said to be a member of the "Scattered Spider" hacking group.
The same group is reportedly also behind the attacks on Co-op and Marks & Spencer.