How the Caesars hack happened: a con at the outsourced IT help desk
The attackers who got into Caesars Entertainment in 2023 did not break through the casino giant's own defenses. They talked their way past an outside company that provided its IT support.[1] This case file covers how a phone-and-chat con at a vendor led to the theft of a loyalty database, the reported $15 million ransom, and the one control that would have closed the door.
What happened
According to Caesars' later breach notices, an unauthorized party got into its systems on August 18, 2023, and began taking data on August 23.[3] The way in was what Caesars called a social engineering attack on an outsourced IT support vendor: someone persuaded the vendor's staff to help them, rather than hacking anything.[1]
On September 7, 2023, Caesars determined that the attackers had copied its loyalty program database. For what the company called a significant number of members, that database held driver's license numbers, Social Security numbers, or both.[1] Caesars said it found no sign that passwords, bank account details or payment card data were taken.[1]
On September 14, 2023, Caesars disclosed the attack in a filing with the Securities and Exchange Commission. The same day, news reports said the company had paid about $15 million to the attackers, after a demand of about $30 million, to keep the stolen data from being released.[2][3] Caesars' filing said only that it had taken steps to make sure the stolen data was deleted, and that it could not guarantee that result.[1]
How they got in
Help desks exist to fix problems quickly: reset a password, restore a login, get someone back to work. That speed is exactly what social engineers use. By posing convincingly as someone entitled to help, an attacker can get a support worker to hand over access that no amount of technical hacking would have produced.[1][2]
In this case the help desk did not even belong to Caesars. It was run by an outside vendor, which meant Caesars' security depended on how carefully another company checked callers. Reports linked the attack to the same crew that hit rival MGM Resorts that month, where attackers were reported to have phoned the IT help desk while posing as an employee.[3][4]
How it was caught
Caesars said it detected suspicious activity, called in outside security experts and notified law enforcement and state gaming regulators.[1] Its customer-facing operations were not disrupted, which is one reason the attack drew far less public attention at first than the MGM outage.[1]
In October 2023, Caesars began mailing breach notices. A filing with the Maine attorney general's office listed 41,397 Maine residents among those affected, and said names and driver's license or ID numbers were among the data taken.[3] Caesars offered affected people 2 years of free credit monitoring and identity theft protection.[3]
In November 2024, federal prosecutors in Los Angeles charged 5 young men, described in news coverage as members of the same loose hacking crew, with conspiracy, wire fraud and identity theft.[4] Those charges are allegations, and the coverage tied them to the group's wider phishing campaign against many companies.[4]
What it cost
Caesars said at the time that it did not expect the incident to have a material effect on its finances, while noting it was still counting the expense.[1] The reported payment of about $15 million was on top of response costs, monitoring for customers, and the legal claims that typically follow a breach like this.[2][3] Paying also carried a risk that Caesars itself acknowledged: there is no way to be sure a criminal actually deletes what was stolen.[1]
The missing control
The missing control: strong identity verification at the help desk, including at any vendor that handles support for you.
A password reset or new login should never be granted just because a caller sounds confident, knows an employee's name, or claims to be in a hurry. If the vendor's staff had been required to confirm the caller's identity through a separate, trusted route, such as a callback to a number on file, a manager's approval, or a video check against a known photo, the con would have hit a wall at the first step. Everything that followed, including the database theft and the ransom, depended on that one bad reset.
Outsourcing the help desk does not outsource the risk. Caesars' own filing named the vendor as the way in.[1]
What to do in your business
- Set a reset rule and write it down. No password or two-factor reset over the phone or chat without a callback to a number already on file, or approval from the person's manager.
- Put it in your IT contract. If an outside company handles your support, ask in writing how they verify callers, and require that they follow your reset rule.
- Protect admin accounts extra. Resets for owners, finance staff and anyone with admin rights should need two people to approve.
- Alert the real user. Make sure staff get an automatic notice when their password or sign-in method changes, so a fake reset gets reported fast.
- Keep less sensitive data. If you do not need copies of driver's licenses or Social Security numbers, stop collecting them, and delete old ones you are not required to keep.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: How to manage vendor, IT provider and contractor access to your systems
- How the Target breach happened: a vendor's billing login and the alarms nobody answered
- How the SolarWinds hack happened: malware shipped as a trusted update
- What caused the Marriott breach: the intruder that came with Starwood
- How the Bybit hack happened: a vendor's laptop and a screen that lied
- The C&M Software hack: a sold login and $140 million from Brazil's bank reserves
- How the $45 million ATM heist worked: prepaid cards with no limits
- Every vendors and third parties control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.