Caesars Entertainment disclosed a breach following an intrusion around 7 September 2023, describing a social engineering attack against an outsourced IT support vendor. Reporting describes the attackers impersonating an employee and persuading the vendor to supply credentials for the company’s identity provider.
A copy of the loyalty programme database was taken, including driver’s licence numbers and social security numbers for a significant number of members. Caesars reportedly paid approximately $15 million against a $30 million demand. Days later the same actor cluster reached MGM Resorts, which we filed at 23-0911 and which did not pay.
The Natural Experiment Nobody Wanted
Two comparable operators, the same sector, the same week, the same actor cluster, opposite decisions. This corpus rarely gets a comparison this controlled — 22-0808 is the only other one it holds.
MGM absorbed days of visible operational disruption. Caesars paid and kept operating. Read narrowly, paying looks like the better commercial outcome, and the desk records that plainly rather than pretending otherwise.
What The Payment Did Not Buy
The loyalty database had already been copied. Payment cannot un-copy it, and the identity documents inside it — licence numbers, social security numbers — are exactly the category we have recorded as unfixable at 22-0922, 26-0726 and 26-0721b.
So the money bought a promise of deletion and of silence from a party whose business is breaking promises. The members of that loyalty programme received the same exposure they would have received had nobody paid, and no part of the $15 million was spent on them.
The Help Desk, Again
The route was a person talking to another person and being believed. We filed that at 22-0120, where an identity provider was reached through its outsourced support desk, at 26-0713, and across the Scattered Spider files at 26-0725 and 26-0716b.
A support desk exists to restore access to people who have lost it, and the harder it is to socially engineer, the worse it is at that job. This is a genuine design tension rather than negligence, and the corpus has yet to file an organisation that has resolved it.
Compiled from contemporaneous reporting and Caesars’ regulatory disclosure, listed below. The ~$15 million payment against a ~$30 million demand is reported and has not been confirmed by the company; it is carried as reported and is the principal reason this file is graded medium. The comparison with MGM at 23-0911 concerns the disclosed facts of two incidents and is not a claim that the two were run identically. No affected-member count is asserted — none was published in a form this desk can carry. Corrections: corrections@forensicpost.com.