{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-caesars-pays-reported-15m-ransom-after-outsourced-it-vendor-is-socially"},"incident":{"title":"Caesars pays reported $15M ransom after outsourced IT vendor is socially engineered","date":"2023-08-18","date_precision":"day","victim_org":"Caesars Entertainment","sector":"Gaming & Casino","country":"United States","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Help Desk Impersonation","Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Extortion","Wire Fraud / Financial Loss"],"loss_usd":15000000,"loss_note":"Reported ransom payment of roughly $15 million, about half of an initial $30 million demand, per Bloomberg and other reporting; Caesars confirmed in its 8-K that it took steps to ensure the stolen data was deleted but did not confirm the amount.","records_affected":null,"threat_actor":"Scattered Spider, reportedly working with ALPHV/BlackCat","summary":"Caesars told the SEC that a social engineering attack on an outsourced IT support vendor gave attackers unauthorised access on 18 August 2023, with data taken on 23 August and the incident discovered on 7 September. The loyalty programme database was stolen, including Social Security and driver's licence numbers; roughly 41,397 Maine residents were among those notified. Caesars reportedly paid millions to prevent publication. Payment card and bank account data were not accessed.","how_it_worked":"Caesars outsourced IT support, so the people who could reset credentials sat at a vendor, outside Caesars' own security culture and monitoring. The actors called that vendor's support staff impersonating Caesars employees, used voice-phishing techniques to get MFA enrolments changed, and inherited the identity of a real user. From there the path to the loyalty database was ordinary authorised access rather than exploitation. The extortion followed the same double-track playbook the group used against MGM the same month: steal first, threaten publication, negotiate.","lessons":"Extending help-desk identity-proofing standards, monitoring and MFA-reset approvals contractually into outsourced IT support is the control gap this incident exposed.","confidence":"Confirmed","sources":[{"title":"Caesars Entertainment says social-engineering attack behind August breach","url":"https://www.cybersecuritydive.com/news/caesars-social-engineering-breach/695995/","publisher":"Cybersecurity Dive"},{"title":"Scattered Spider (AA23-320A)","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a","publisher":"CISA / FBI"}],"entry_type":"incident","slug":"2023-caesars-pays-reported-15m-ransom-after-outsourced-it-vendor-is-socially","year":2023,"loss_kind":"ransom_paid","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-caesars-pays-reported-15m-ransom-after-outsourced-it-vendor-is-socially"}}