2023-09-14 (disclosed) · US · Caesars Entertainment
Caesars loyalty database taken after IT vendor social engineering, 2023
Disclosed by the affected organisation.
Caesars Entertainment disclosed in September 2023 that suspicious activity in its network resulted from a social engineering attack on an outsourced IT support vendor. The attacker acquired a copy of its loyalty program database, including driver's licence and Social Security numbers for a significant number of members. Caesars said it had taken steps to ensure the stolen data was deleted but could not guarantee it. TechCrunch relayed a Wall Street Journal report that Caesars paid about half of a $30 million demand.
Timeline
- 2023-09-07 Caesars determines that the attacker acquired a copy of its loyalty program database.
- 2023-09-14 Caesars discloses the incident in a Form 8-K, saying it began with social engineering of an outsourced IT support vendor.
Lessons
- Hold outsourced IT support to the same identity verification rules as your own help desk, and audit them.
- Know which vendors can reset credentials in your environment and what they can reach.
- Paying for deletion gives no guarantee: Caesars itself said it could not guarantee the data was deleted.
Scam types: Help desk password and MFA reset impersonation, Data theft extortion
Sources
- Caesars Entertainment: Form 8-K (14 September 2023) (Company disclosure, primary, accessed 2026-09-24)
- TechCrunch: Hackers claim MGM cyberattack as outage drags into fourth day (News report, secondary, accessed 2026-09-24)