Desk live·
ForensicPost
Ransomware/Aftermath/File 23-0907

Caesars Paid About $15 Million While MGM Refused in the Same Week

Caesars was reached through an outsourced IT vendor talked into handing over credentials, and reportedly paid around $15 million. MGM, filed at 23-0911, did not. The loyalty database was gone either way.

Constructed geometry · not a chart of case data
JurisdictionUSALas Vegasthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetCaesars Entertainment
ActorScattered Spider
D. Kennedy12 min readConfidence: medium2 sources reviewed

Caesars Entertainment disclosed a breach following an intrusion around 7 September 2023, describing a social engineering attack against an outsourced IT support vendor. Reporting describes the attackers impersonating an employee and persuading the vendor to supply credentials for the company’s identity provider.

A copy of the loyalty programme database was taken, including driver’s licence numbers and social security numbers for a significant number of members. Caesars reportedly paid approximately $15 million against a $30 million demand. Days later the same actor cluster reached MGM Resorts, which we filed at 23-0911 and which did not pay.

The Natural Experiment Nobody Wanted

Two comparable operators, the same sector, the same week, the same actor cluster, opposite decisions. This corpus rarely gets a comparison this controlled — 22-0808 is the only other one it holds.

MGM absorbed days of visible operational disruption. Caesars paid and kept operating. Read narrowly, paying looks like the better commercial outcome, and the desk records that plainly rather than pretending otherwise.

What The Payment Did Not Buy

The loyalty database had already been copied. Payment cannot un-copy it, and the identity documents inside it — licence numbers, social security numbers — are exactly the category we have recorded as unfixable at 22-0922, 26-0726 and 26-0721b.

So the money bought a promise of deletion and of silence from a party whose business is breaking promises. The members of that loyalty programme received the same exposure they would have received had nobody paid, and no part of the $15 million was spent on them.

The Help Desk, Again

The route was a person talking to another person and being believed. We filed that at 22-0120, where an identity provider was reached through its outsourced support desk, at 26-0713, and across the Scattered Spider files at 26-0725 and 26-0716b.

A support desk exists to restore access to people who have lost it, and the harder it is to socially engineer, the worse it is at that job. This is a genuine design tension rather than negligence, and the corpus has yet to file an organisation that has resolved it.

How we reported this

Compiled from contemporaneous reporting and Caesars’ regulatory disclosure, listed below. The ~$15 million payment against a ~$30 million demand is reported and has not been confirmed by the company; it is carried as reported and is the principal reason this file is graded medium. The comparison with MGM at 23-0911 concerns the disclosed facts of two incidents and is not a claim that the two were run identically. No affected-member count is asserted — none was published in a form this desk can carry. Corrections: corrections@forensicpost.com.

Sources
  1. Caesars Entertainment Reveals Major Ransomware BreachInfosecurity Magazine
  2. Caesars Entertainment cyberattack and MGM Resorts data breachFortune
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary