Threat Spotlight
Case 02Aug 2023

Caesars Entertainment

Las Vegas StripSocial-engineered outsourced help-desk vendorScattered Spider(reported)
Ransom demand
~$30M
Per public reporting
Ransom paid
~$15M
Bloomberg / WSJ
Disclosure
Sep 7 2023
SEC 8-K filing
Vector
Vendor SE
Outsourced IT support
Operations
Stayed up
Unlike MGM

Caesars was breached weeks before MGM, but unlike MGM the attack vector ran through an outsourced IT support vendor rather than Caesars' own help desk. Reporting indicates the operators social-engineered the third party, then pivoted into Caesars' environment using that relationship.

The operators obtained Caesars Rewards loyalty-program data including driver's license numbers and Social Security numbers for “a significant number” of program members. The breach was disclosed in an SEC 8-K filing on September 7, 2023, three days before MGM's intrusion became publicly known.

Multiple outlets including Bloomberg and the Wall Street Journal reported that Caesars paid approximately $15 million of an initial $30 million ransom demand. Caesars kept its consumer-facing operations running through the incident, which several analysts attributed to the decision to pay.

The Caesars chain illustrates a risk small businesses share with megacorps: your security perimeter ends at the worst-trained person at any vendor you rely on. The Caesars employees did not click a phishing link. The Caesars help desk did not reset an MFA token. The attack succeeded somewhere outside the Caesars network.

Sources

Caesars Entertainment SEC Form 8-K (Sep 7, 2023); Bloomberg, Wall Street Journal, Reuters; KrebsOnSecurity; Mandiant + Microsoft threat-actor briefings. Ransom payment figure is reported, not officially confirmed by Caesars.

Want to know if your business survives this playbook?

Free 15-minute call. We'll walk through your help-desk process, MFA setup, and three things you can fix this week.

Book a free consultation