/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Sources: Caesars Entertainment paid tens of millions of dollars to hackers who breached the company's systems in recent weeks and threatened to release the data

- Hackers stole data, extorted company, people familiar said  — Caesars breach came in weeks before MGM announced cyberattack

Bloomberg William Turton

Context & Ripple Effects

This report put a price tag on Caesars' response to data-extortion pressure. Follow-up coverage tied the intrusion to a social-engineering attack on an outsourced IT support vendor, shifting attention from the casino operator's own perimeter to a supplier-mediated access path.

The episode unfolded alongside a disruptive MGM incident: MGM's website remained offline for more than 60 hours after its attack. Later reporting connected both companies to help-desk calls involving the same named groups, making the pair a useful comparison of ransomware response choices.

First-order effects

  • Caesars faces an immediate cash cost from the reported payment while still having to manage the consequences of stolen data and the attackers' release threat.
  • Its outsourced IT-support access and help-desk verification processes become an urgent remediation target, not merely a back-office vendor issue.

Second-order effects

  • MGM and other hospitality operators have a concrete contrast between paying an extortion demand and absorbing disruption: MGM later reported it refused to pay and expected a more than $100M quarterly impact.
  • Identity and support vendors serving large enterprises face stronger customer scrutiny over how phone-based requests can lead to account or system access.

Third-order effects

  • If this pattern persists, ransomware resilience will be evaluated as much through third-party identity controls and recovery capability as through traditional network defenses.
  • The Caesars-MGM comparison may push boards to treat ransom decisions as a broader operational-continuity and data-governance choice, though outcomes will remain highly incident-specific.

The trend: Social-engineering attacks against outsourced identity and support workflows are making third-party access a central ransomware risk for large consumer businesses.

Discussion

  • @mranthropology.bsky.social Rich Stroffolino on bluesky
    Interesting timing considering the MGM attack 👀 [embedded post]
  • @williamturton William Turton on x
    caesars just confirmed it was hacked in an SEC filing just now [image]
  • @vitalvegas Vital Vegas on x
    Rumors of Caesars Entertainment paying $30 million to hackers in recent data breach are unfounded. That was the demand, the ransom paid was $15 million (covered by insurance), or about two hours of revenue in Caesars Palace high limit salon. https://www.casino.org/...
  • @rotopat Patrick Daugherty on x
    Love the future
  • @mikko @mikko on x
    «Our sources say Caesars Entertainment paid $15 million to the hackers to resolve its data breach. The original demand was $30 million. Caesars talked them down like an episode of “Pawn Stars.”» https://www.casino.org/...
  • @williamturton William Turton on x
    scoop - caesars entertainment inc paid millions in a ransom to hackers in recent weeks. the hacking group responsible is believed to be comprised of people 19-22 years old in the US and UK. the same group hit MGM resorts. story tk 🎰
  • r/technology r on reddit
    Caesars reportedly paid millions to stop hackers releasing its data |  It's the second Las Vegas casino group to be attacked this week.
  • r/technews r on reddit
    Caesars reportedly paid millions to stop hackers releasing its data |  It's the second Las Vegas casino group to be attacked this week.
  • r/vegas r on reddit
    Caesars Entertainment Paid Millions in Ransom in Recent Attack
  • @zackwhittaker@mastodon.social Zack Whittaker on mastodon
    Bloomberg is reporting that the same hackers who took down MGM Resorts this week recently targeted Caesars Entertainment, which paid millions in ransom to stop the publishing of its sensitive information.  —  The hacking group behind the attacks is believed to be Scattered Spider…
  • @vxunderground @vxunderground on x
    All ALPHV ransomware group did to compromise MGM Resorts was hop on LinkedIn, find an employee, then call the Help Desk. A company valued at $33,900,000,000 was defeated by a 10-minute conversation.
  • @_sn0ww Snow on x
    Chances are, if you stopped in the @sec_defcon this year at @defcon, you heard first hand how successful #vishing can be. 🧵
  • @vxunderground @vxunderground on x
    @let_svn No, this isn't an attempt to screw anyone over. This particular subgroup of ALPHV ransomware has established a reputation of being remarkably gifted at social engineering for initial access. It isn't really a surprise ALPHV (or the subgroup) is behind this attack.
  • @racheltobac Rachel Tobac on x
    One of the easiest ways for me to hack is simply: 1. Look up who works at a org on LinkedIn 2. Call Help Desk (spoof phone number of person I'm impersonating) 3. Tell Help Desk I lost access to work account & help me get back in I hope we learn more & get confirmation of methods
  • @vxunderground @vxunderground on x
    @arborbytes The Threat Actors themselves
  • @vxunderground @vxunderground on x
    Very cool. Thank you @Bitdefender and @TrustedSec for the kind words when speaking with @Forbes. However, we would like to note vx-underground is a collective of several people - it is not a single person. (TrustedSec knows this, maybe Mr. Hammerstone made an oopsie doopsie) [ima…