Filing: Caesars confirms the casino operator was hacked via a social engineering attack on an outsourced IT support vendor; sources: Caesars paid a ~$15M ransom
CURRENT REPORT Pursuant to Section 13 or 15(d) of the Securities Exchange Act … Thomas Barrabi / New York Post : Caesars Entertainment paid about $15M to hackers who stole customer Social Security numbers, other info: report Michael Kan / PCMag : After MGM Resort Hack, Caesars Entertainment Also Reports a Breach Ryan Naraine / SecurityWeek : Caesars Confirms Ransomware Hack, Stolen Loyalty Program Database AJ Vicens / CyberScoop : Groups linked to Las Vegas cyber attacks are prolific criminal hacking gangs Cybersecurity Dive : MGM Resorts disruption linked to recent attacks against hospitality industry Kevin Hurler / Gizmodo : Caesars Entertainment Confirms Hack in Second Recent Casino Attack Zeba Siddiqui / Reuters : Casino giant Caesars confirms data breach Zack Whittaker / TechCrunch : Caesars Entertainment says customer data stolen in cyberattack William Turton / Las Vegas Review-Journal : Caesars Entertainment paid millions in recent cyberattack, sources say Piero Cingari / Benzinga : Casino Giants Face Cybersecurity Crisis: Caesars Entertainment Falls Prey To Hackers Post-MGM Attack Fox 5 Las Vegas : Report: Caesars Entertainment recently hacked by same group claiming attack against MGM iTnews : MGM Resorts breached by ‘Scattered Spider’ hackers Todd Shriber / Casino.org : Caesars Reportedly Paid Cyber Ransom, MGM Credit Rating Vulnerable Following Hack Seher Dareen / Reuters : Caesars Entertainment paid heavy ransom after cyberattack - Bloomberg News Mathew J. Schwartz / InfoRiskToday.com : Caesars Entertainment Reportedly Pays Ransom to Attackers William Turton / Bloomberg : Sources: Caesars Entertainment paid tens of millions of dollars to hackers who breached the company's systems in recent weeks and threatened to release its data Mastodon: @megazone@infosec.exchange : Let me get this straight... The attacks are centered in Vegas, on Caesars and MGM, attributed to a group ‘known for using social engineering schemes’ to obtain legit credentials, and the first signs surfaced in early September - which means they probably obtained access in August. — We're all thinking it, right? … Brett Callow / @brett@infosec.exchange : Scattered Spider, who told @vxunderground they were behind an attack on #MGM, are also said to be behind an earlier attack on Caesars Entertainment. — https://www.bloomberg.com/... Brett Callow / @brett@infosec.exchange : The hackers demanded $30 million, and the company agreed to pay about half of that amount, according to a person familiar with the matter. #CaesarsPalace #ScatteredSpider — https://www.wsj.com/... Zack Whittaker / @zackwhittaker@mastodon.social : Bloomberg is reporting that the same hackers who took down MGM Resorts this week recently targeted Caesars Entertainment, which paid millions in ransom to stop the publishing of its sensitive information. — The hacking group behind the attacks is believed to be Scattered Spider, aka 0ktapus, comprised mostly of young adults. … Bluesky: @waxmonkey.bsky.social : im tellin ya griftops, casinos have the cash and the motivation to end things quickly and quietly so stay the fuck away from public utilities and schools and shit and go where the money is high and the transparency is low and i will hate you ten to fifteen percent less [embedded post] Rich Stroffolino / @mranthropology.bsky.social : Interesting timing considering the MGM attack 👀 [embedded post] X: @vxunderground : Do wE kNoW iF CaEsArS wAs HaCkeD?! Yes, they were compromised around the exact same time as MGM and access to Caesar's was compromised using the exact same technique that was used against MGM. Read the U.S. Securities and Exchange Commission report, nerds. [image] Andrew Shikiar / @andrewshikiar : I'm often asked about FIDO ROI calculators.. no need to sharpen your pencils for this one: Option 1: pay ransomware thugs $15M+ after they social engineer password from your IT team Option 2: deploy FIDO Security Keys, which prevent MFA bypass attacks https://www.wsj.com/... Will / @bushidotoken : Caesars “identified suspicious activity in its [IT] network resulting from a social engineering attack on an outsourced IT support vendor” they use Circumstantial evidence here, but this is similar to prior #ScatteredSpider attacks on BPO firms https://www.crowdstrike.com/ ... Justin Elze / @hackinglz : I'm not sure why casinos wouldn't pay a ransomware group. The loss per hour/day they face is on the extreme side compared to many other targeted verticals. The obvious downside here is it fuels capabilities, but the business side of paying is logical, assuming they use this event... Sean Lyngaas / @snlyngaas : Then there's this sentence 🧐 ; ) “We have taken steps to ensure that the stolen data is deleted by the unauthorized actor, although we cannot guarantee this result.” Dr. Wesley McGrew / @mcgrewsecurity : Ransoms have been being paid across industries, which is why it's been “open season” pretty consistently for ransomware for the past decade. This almost certainly isn't even the first casino/resort company that's paid. Carly Page / @carlypage_ : Caesars Entertainment has confirmed that hackers stole a huge trove of customer data in a recent cyberattack, including driver's license numbers and Social Security numbers for a “significant number of members”. @zackwhittaker has more: https://techcrunch.com/... William Turton / @williamturton : caesars just confirmed it was hacked in an SEC filing just now [image] Vital Vegas / @vitalvegas : Rumors of Caesars Entertainment paying $30 million to hackers in recent data breach are unfounded. That was the demand, the ransom paid was $15 million (covered by insurance), or about two hours of revenue in Caesars Palace high limit salon. https://www.casino.org/... Patrick Daugherty / @rotopat : Love the future @mikko : «Our sources say Caesars Entertainment paid $15 million to the hackers to resolve its data breach. The original demand was $30 million. Caesars talked them down like an episode of “Pawn Stars.”» https://www.casino.org/... William Turton / @williamturton : scoop - caesars entertainment inc paid millions in a ransom to hackers in recent weeks. the hacking group responsible is believed to be comprised of people 19-22 years old in the US and UK. the same group hit MGM resorts. story tk 🎰 LinkedIn: Frank Sargent : 10 Minutes you say? — I have said forever in my workshops - that one of the most effective spends within your cyber budget would be effective security awareness training.. … Forums: r/technology : Caesars reportedly paid millions to stop hackers releasing its data | It's the second Las Vegas casino group to be attacked this week. r/technology : Over the past few weeks, MGM and Caesars were both hacked by one of the most ‘aggressive threat actors’ targeting the U.S. r/vegas : Caesars Entertainment Paid Millions in Ransom in Recent Attack r/technews : Caesars reportedly paid millions to stop hackers releasing its data | It's the second Las Vegas casino group to be attacked this week.
Context & Ripple Effects
The disclosure follows a report that Caesars had negotiated with the attackers and arrives amid a parallel disruption at MGM, whose website had remained unavailable for more than 60 hours after its own attack.
The shared pattern became clearer in subsequent coverage: Okta said MGM, Caesars and other clients were compromised through help-desk calls, tying the incidents to a reusable social-engineering route rather than an isolated casino-system failure.
First-order effects
- Caesars must manage the exposure of customer Social Security and driver's-license numbers, along with loyalty-program data, after confirming the compromise.
- The company’s outsourced IT support vendor becomes a central security and accountability point; sources’ report of an approximately $15M payment also puts its breach response under scrutiny.
Second-order effects
- Hospitality operators and their vendors face pressure to tighten help-desk identity verification and limit the access that a socially engineered support interaction can unlock, especially after reports of similar help-desk compromises affecting multiple clients.
- MGM’s concurrent outage illustrates the operating risk for casino businesses: a breach can disrupt customer-facing systems as well as expose data, increasing the cost of a weak vendor-access path.
Third-order effects
- If attackers can repeatedly turn outsourced support channels into privileged access, third-party identity controls will become a more consequential differentiator in enterprise security procurement and vendor oversight.
- The paired Caesars and MGM cases point to extortion groups targeting concentrated service workflows, potentially shifting cyber-risk management from perimeter defense toward controls over people, support processes and delegated access.
The trend: Social engineering is becoming a scalable entry point for ransomware and extortion campaigns against enterprises that rely on outsourced support and centralized identity workflows.