Caesars Entertainment disclosed loyalty database theft and paid a ransom
- Organization
- Caesars Entertainment
- Exploit
- Ransomware
- Industry
- Hospitality and Gaming
Caesars Entertainment told the US Securities and Exchange Commission in a Form 8-K filed on September 14, 2023 that an unauthorized actor had obtained a copy of its loyalty program database. The company said it identified suspicious activity following a social engineering attack on an outsourced IT support vendor, and determined on September 7 that the database had been taken.
The database contained driver's licence numbers and Social Security numbers for what the filing described as a significant number of members. Caesars said it had no evidence that member passwords or PINs, bank account details or payment card data had been acquired. It acknowledged that other data had also been stolen but declined to specify what.
Unlike the concurrent attack on MGM Resorts, Caesars said its customer-facing operations, including its casinos and its online and mobile applications, had not been disrupted.
Caesars said it had taken steps to ensure the stolen data was deleted by the unauthorized actor, while adding that it could not guarantee that result. The Wall Street Journal reported that the company paid roughly $15 million against an initial demand of $30 million. Bloomberg attributed the intrusion to Scattered Spider, also tracked as UNC3944 and 0ktapus, though TechCrunch reported that the group denied involvement in the Caesars breach while claiming responsibility for the MGM attack.