Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Caesars Entertainment Breach 2023: How Social Engineering of…
Breach analysis Incident: 14 Sep 2023

Caesars Entertainment Breach 2023: How Social Engineering of an IT Vendor Led to a Loyalty Database Theft and Ransom

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 29 September 2026 7 min read
Category: Human identity
Attack route: Social engineering
On this page

In September 2023, Caesars Entertainment told US regulators that hackers had stolen a copy of its loyalty programme database, which included driver's licence numbers and Social Security numbers for a "significant number of members." In an 8-K filing on 14 September, the company said the attack began with social engineering against an outsourced IT support vendor, which it did not name. It also said: "We have taken steps to ensure that the stolen data is deleted by the unauthorized actor, although we cannot guarantee this result," wording widely read as confirming a ransom payment. The Wall Street Journal reported that Caesars paid about half of a $30 million demand. Bloomberg linked the attack to the group known as Scattered Spider, the same group reported to be behind the MGM Resorts attack days earlier, although a representative of the group denied involvement with Caesars to TechCrunch. This is a human-identity breach: the way in was a person persuaded to grant access, not a stolen machine credential.

Key takeaways

  • Caesars disclosed on 14 September 2023 that attackers stole a copy of its loyalty programme database, including driver's licence and Social Security numbers.
  • The attack began with social engineering against an outsourced IT support vendor, according to Caesars.
  • Caesars said it had taken steps to have the stolen data deleted; the Wall Street Journal reported it paid about half of a $30 million demand.
  • Bloomberg attributed the attack to Scattered Spider; a representative of the group denied involvement to TechCrunch.
  • The identity lesson: an IT support provider's help desk can hand out access to your estate, so its identity checks are part of your security.

At a glance

OrganisationCaesars Entertainment (hotel and casino operator)
WhenAugust to early September 2023; disclosed 14 September 2023
AttackerScattered Spider (UNC3944), according to Bloomberg; the group denied involvement to TechCrunch
Entry pointSocial engineering of an outsourced IT support vendor
Identities abusedAccess obtained through a third-party IT support provider; details not disclosed
ImpactCopy of the loyalty programme database stolen, including driver's licence and Social Security numbers; ransom reportedly paid
CategoryHuman identity (not listed as an NHI or AI agent breach). Incident class: human-identity breach (IT vendor social engineering)

What happened

Caesars disclosed the attack in an 8-K filing with the US Securities and Exchange Commission on 14 September 2023. TechCrunch reported that hackers stole "a copy of the company's loyalty program database," which included driver's licence and Social Security numbers for what Caesars called a significant number of members. SiliconANGLE reported that Caesars detected the breach in early September after spotting suspicious activity in its network, and noted that the company had said in April that its loyalty programme had more than 65 million members. Caesars said it had no indication that members' passwords or payment card details were accessed, and that its properties and gaming apps were not affected.

The way in was a third party. SiliconANGLE reported that the social engineering attack "didn't target Caesars itself" but an outsourced IT support vendor. TechCrunch reported that Caesars confirmed this in a separate data breach notice. Caesars did not say what the vendor was persuaded to do or which accounts were used.

On payment, Caesars stated: "We have taken steps to ensure that the stolen data is deleted by the unauthorized actor, although we cannot guarantee this result." TechCrunch said this implied a ransom had been paid, and cited the Wall Street Journal's report that Caesars paid about half of the $30 million the hackers demanded. On attribution, TechCrunch reported that Bloomberg linked the attack to Scattered Spider, "known for using social engineering to trick employees into granting access to large corporate networks," but also that "A representative for the Scattered Spider hacking group told TechCrunch that they carried out the cyberattack on MGM, but denied involvement with Caesars." Netwrix, in a later write-up of the MGM attack, dated a Scattered Spider social engineering attack on Caesars' IT support provider to 7 September 2023.

Timeline

DateEvent
August 2023Attackers begin targeting Caesars, according to Bloomberg as reported by TechCrunch and SiliconANGLE.
7 September 2023Social engineering attack on Caesars' IT support provider, according to Netwrix.
13 September 2023Bloomberg reports the attack.
14 September 2023Caesars files an 8-K confirming the theft of its loyalty programme database.

How it happened: the identity attack path

  1. Third-party target. Attackers went after an outsourced IT support vendor rather than Caesars directly.
  2. Social engineering. The vendor was deceived into granting access; Caesars did not say how.
  3. Access to Caesars' network. Caesars later spotted suspicious activity on its internal network.
  4. Data theft. A copy of the loyalty programme database was taken.
  5. Extortion. Caesars took steps to have the data deleted; a ransom payment was reported.

Impact

  • Data: a copy of the loyalty programme database, including driver's licence and Social Security numbers for a significant number of members.
  • Money: about $15 million paid, according to the Wall Street Journal as reported by TechCrunch.
  • Operations: Caesars said customer-facing operations were not affected.

What this means for NHI governance

This is a human-identity breach, flagged as such on our breach hub. The entry point was a person at an IT support provider who was talked into granting access. We include it because the same pattern keeps reaching non-human identities: whoever controls the help desk and identity provider can issue or reset credentials for any account, human or machine, and outsourced support extends that power to another company's staff.

The lesson is that help desk identity checks and third-party access belong in the same risk register as secrets. See our Account Recovery and Help Desk Security Guide and Third-Party Access Guide.

Recommendations

  • Hold outsourced help desks to your own verification standard. Write it into the contract and test it. See our Account Recovery and Help Desk Security Guide.
  • Limit what vendor staff can reset. Keep privileged and identity provider admin accounts out of their reach. See the Third-Party Access Guide.
  • Use phishing-resistant MFA for privileged accounts. Make a reset alone insufficient to take over an admin account. See the MFA Guide.
  • Watch for unusual access after resets. New devices, MFA changes and bulk data access are early signals. See the ITDR Guide.
  • Segment high-value customer data. Loyalty databases holding identity numbers need their own access controls and monitoring.

Frequently asked questions

How was Caesars Entertainment hacked in 2023?

Caesars said the attack began with social engineering against an outsourced IT support vendor. The attackers then stole a copy of its loyalty programme database.

Did Caesars pay a ransom?

Caesars said it had taken steps to have the stolen data deleted. The Wall Street Journal reported it paid about half of a $30 million demand.

Was Scattered Spider behind the Caesars attack?

Bloomberg linked the attack to Scattered Spider. A representative of the group told TechCrunch it attacked MGM Resorts but denied involvement with Caesars.

MGM Resorts Breach 2023 · Co-op Cyber Attack 2025 · Account Recovery and Help Desk Security Guide · Third-Party Access Guide · MFA Guide

How NHI Mgmt Group can help

Help desks and IT vendors can hand out the keys to every account. We help teams tighten identity checks, limit third-party privileges and detect takeovers early. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

    Bonus 33% off our NHI Course when you subscribe.

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 29 September 2026.
    Based on the public sources listed under References. Details may change as investigations continue.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org