Sources: Caesars Entertainment paid tens of millions of dollars to hackers who breached the company's systems in recent weeks and threatened to release the data
- Hackers stole data, extorted company, people familiar said — Caesars breach came in weeks before MGM announced cyberattack
BloombergWilliam Turton
Context & Ripple Effects
This report put a price tag on Caesars' response to data-extortion pressure. Follow-up coverage tied the intrusion to a social-engineering attack on an outsourced IT support vendor, shifting attention from the casino operator's own perimeter to a supplier-mediated access path.
The episode unfolded alongside a disruptive MGM incident: MGM's website remained offline for more than 60 hours after its attack. Later reporting connected both companies to help-desk calls involving the same named groups, making the pair a useful comparison of ransomware response choices.
First-order effects
Caesars faces an immediate cash cost from the reported payment while still having to manage the consequences of stolen data and the attackers' release threat.
Its outsourced IT-support access and help-desk verification processes become an urgent remediation target, not merely a back-office vendor issue.
Identity and support vendors serving large enterprises face stronger customer scrutiny over how phone-based requests can lead to account or system access.
Third-order effects
If this pattern persists, ransomware resilience will be evaluated as much through third-party identity controls and recovery capability as through traditional network defenses.
The Caesars-MGM comparison may push boards to treat ransom decisions as a broader operational-continuity and data-governance choice, though outcomes will remain highly incident-specific.
The trend: Social-engineering attacks against outsourced identity and support workflows are making third-party access a central ransomware risk for large consumer businesses.
Rumors of Caesars Entertainment paying $30 million to hackers in recent data breach are unfounded. That was the demand, the ransom paid was $15 million (covered by insurance), or about two hours of revenue in Caesars Palace high limit salon. https://www.casino.org/...
«Our sources say Caesars Entertainment paid $15 million to the hackers to resolve its data breach. The original demand was $30 million. Caesars talked them down like an episode of “Pawn Stars.”» https://www.casino.org/...
scoop - caesars entertainment inc paid millions in a ransom to hackers in recent weeks. the hacking group responsible is believed to be comprised of people 19-22 years old in the US and UK. the same group hit MGM resorts. story tk 🎰
Bloomberg is reporting that the same hackers who took down MGM Resorts this week recently targeted Caesars Entertainment, which paid millions in ransom to stop the publishing of its sensitive information. — The hacking group behind the attacks is believed to be Scattered Spider…
All ALPHV ransomware group did to compromise MGM Resorts was hop on LinkedIn, find an employee, then call the Help Desk. A company valued at $33,900,000,000 was defeated by a 10-minute conversation.
@let_svn No, this isn't an attempt to screw anyone over. This particular subgroup of ALPHV ransomware has established a reputation of being remarkably gifted at social engineering for initial access. It isn't really a surprise ALPHV (or the subgroup) is behind this attack.
One of the easiest ways for me to hack is simply: 1. Look up who works at a org on LinkedIn 2. Call Help Desk (spoof phone number of person I'm impersonating) 3. Tell Help Desk I lost access to work account & help me get back in I hope we learn more & get confirmation of methods
Very cool. Thank you @Bitdefender and @TrustedSec for the kind words when speaking with @Forbes. However, we would like to note vx-underground is a collective of several people - it is not a single person. (TrustedSec knows this, maybe Mr. Hammerstone made an oopsie doopsie) [ima…