Twenty Years of Getting It Wrong: The Breaches and Blunders That Defined Modern Cybersecurity
From MGM's identity disaster to MOVEit's patch pile-up, the same failure modes keep appearing in postmortems. That's the problem.

Key points
- The MGM Resorts breach and the Caesars Entertainment ransomware payment in 2023 exposed how social engineering defeats even well-funded enterprise identity controls.
- Progress Software's MOVEit Transfer vulnerabilities triggered a mass-exploitation event in 2023 affecting hundreds of downstream organizations.
- Two decades of high-profile incidents show systemic failures in patch management and credential hygiene that repeat across generations of security teams.
- Dark Reading's retrospective catalogs moments that produced genuine organizational change alongside moments that produced nothing except a revised incident response slide deck.
Two decades. Same postmortem.
The MGM situation in 2023 still stings if you spent any time running identity pipelines. Attackers called the help desk. No zero-day, no implant chain: a phone call defeated an enterprise identity stack worth millions. The failure isn't technical. Organizations build elaborate controls inside their perimeter and leave human verification running on vibes and brand familiarity.
Caesars paid. Quietly. Which tells you everything about how the ransomware calculus actually works in boardrooms versus how it gets discussed at security conferences. We first covered Caesars Entertainment's exposure on 2 July 2026.
Should you worry about MOVEit-style supply chain hits?
Yes, because the conditions that produced them haven't changed. Progress Software's managed file transfer product became the supply chain domino of 2023, with the SQL injection flaw tracked as CVE-2023-34362 hitting organizations before most had finished their morning stand-ups. The lesson isn't that zero-days happen. It's that file transfer appliances sit in network DMZs, touch sensitive data, and get patched last because nobody owns them cleanly. They live in the gap between the platform team and the security team.
That gap is where most of these incidents actually live.
Dark Reading's retrospective spans blunders from straightforward misconfigurations to genuinely baffling executive decisions. What the pattern shows across twenty years is not an escalating sophistication problem. Attackers get more efficient, but the underlying entry points, unpatched internet-facing services and third-party access that never got revoked, have occupied the same ground since the early 2000s.
The postmortem will say it every time: the indicator was visible in logs before the breach was confirmed. Somewhere in an S3 access log, a VPC flow log, or an Azure Monitor workspace, the data existed. Nobody was looking. Given that our 2026 vendor survey found practitioner awareness up and resilience flat, that sentence lands harder than it should.
Patch your internet-facing file transfer services before you build the threat model.



