Skip to content
NetarxImpact Database
Vendor / Supply Chain ImpersonationNo AI reportedConfirmed

Caesars pays reported $15M ransom after outsourced IT vendor is socially engineered

Caesars Entertainment · Gaming & Casino · United States · August 18, 2023

Ransom paid
$15,000,000
An extortion payment the victim chose to make.
Reported ransom payment of roughly $15 million, about half of an initial $30 million demand, per Bloomberg and other reporting; Caesars confirmed in its 8-K that it took steps to ensure the stolen data was deleted but did not confirm the amount.

What happened

Caesars told the SEC that a social engineering attack on an outsourced IT support vendor gave attackers unauthorised access on 18 August 2023, with data taken on 23 August and the incident discovered on 7 September. The loyalty programme database was stolen, including Social Security and driver's licence numbers; roughly 41,397 Maine residents were among those notified. Caesars reportedly paid millions to prevent publication. Payment card and bank account data were not accessed.

How the deception worked

Caesars outsourced IT support, so the people who could reset credentials sat at a vendor, outside Caesars' own security culture and monitoring. The actors called that vendor's support staff impersonating Caesars employees, used voice-phishing techniques to get MFA enrolments changed, and inherited the identity of a real user. From there the path to the loyalty database was ordinary authorised access rather than exploitation. The extortion followed the same double-track playbook the group used against MGM the same month: steal first, threaten publication, negotiate.

AI involvement · No AI reported

No AI involvement reported.

The control that would have caught it· our reading, not a claim from the sources

Extending help-desk identity-proofing standards, monitoring and MFA-reset approvals contractually into outsourced IT support is the control gap this incident exposed.

Sources (2)

  1. Caesars Entertainment says social-engineering attack behind August breach
    Cybersecurity Dive·cybersecuritydive.comOpen ↗
  2. Scattered Spider (AA23-320A)
    CISA / FBI·cisa.govOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.