Case file · CAESARS 2023

How the Caesars hack happened: a con at the outsourced IT help desk

Published 2026-09-29 · 4 min read · Missing control: Help desk identity verification

The attackers who got into Caesars Entertainment in 2023 did not break through the casino giant's own defenses. They talked their way past an outside company that provided its IT support.[1] This case file covers how a phone-and-chat con at a vendor led to the theft of a loyalty database, the reported $15 million ransom, and the one control that would have closed the door.

What happened

According to Caesars' later breach notices, an unauthorized party got into its systems on August 18, 2023, and began taking data on August 23.[3] The way in was what Caesars called a social engineering attack on an outsourced IT support vendor: someone persuaded the vendor's staff to help them, rather than hacking anything.[1]

On September 7, 2023, Caesars determined that the attackers had copied its loyalty program database. For what the company called a significant number of members, that database held driver's license numbers, Social Security numbers, or both.[1] Caesars said it found no sign that passwords, bank account details or payment card data were taken.[1]

On September 14, 2023, Caesars disclosed the attack in a filing with the Securities and Exchange Commission. The same day, news reports said the company had paid about $15 million to the attackers, after a demand of about $30 million, to keep the stolen data from being released.[2][3] Caesars' filing said only that it had taken steps to make sure the stolen data was deleted, and that it could not guarantee that result.[1]

How they got in

Help desks exist to fix problems quickly: reset a password, restore a login, get someone back to work. That speed is exactly what social engineers use. By posing convincingly as someone entitled to help, an attacker can get a support worker to hand over access that no amount of technical hacking would have produced.[1][2]

In this case the help desk did not even belong to Caesars. It was run by an outside vendor, which meant Caesars' security depended on how carefully another company checked callers. Reports linked the attack to the same crew that hit rival MGM Resorts that month, where attackers were reported to have phoned the IT help desk while posing as an employee.[3][4]

How it was caught

Caesars said it detected suspicious activity, called in outside security experts and notified law enforcement and state gaming regulators.[1] Its customer-facing operations were not disrupted, which is one reason the attack drew far less public attention at first than the MGM outage.[1]

In October 2023, Caesars began mailing breach notices. A filing with the Maine attorney general's office listed 41,397 Maine residents among those affected, and said names and driver's license or ID numbers were among the data taken.[3] Caesars offered affected people 2 years of free credit monitoring and identity theft protection.[3]

In November 2024, federal prosecutors in Los Angeles charged 5 young men, described in news coverage as members of the same loose hacking crew, with conspiracy, wire fraud and identity theft.[4] Those charges are allegations, and the coverage tied them to the group's wider phishing campaign against many companies.[4]

What it cost

Caesars said at the time that it did not expect the incident to have a material effect on its finances, while noting it was still counting the expense.[1] The reported payment of about $15 million was on top of response costs, monitoring for customers, and the legal claims that typically follow a breach like this.[2][3] Paying also carried a risk that Caesars itself acknowledged: there is no way to be sure a criminal actually deletes what was stolen.[1]

The missing control

The missing control: strong identity verification at the help desk, including at any vendor that handles support for you.

A password reset or new login should never be granted just because a caller sounds confident, knows an employee's name, or claims to be in a hurry. If the vendor's staff had been required to confirm the caller's identity through a separate, trusted route, such as a callback to a number on file, a manager's approval, or a video check against a known photo, the con would have hit a wall at the first step. Everything that followed, including the database theft and the ransom, depended on that one bad reset.

Outsourcing the help desk does not outsource the risk. Caesars' own filing named the vendor as the way in.[1]

What to do in your business

Watch the case
How Hackers Got Past Caesars Through Its IT VendorDrops 2026-11-22
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More vendors and third parties cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. SEC: Caesars Entertainment Form 8-K, September 14, 2023
  2. CNBC: Caesars paid millions in ransom to cybercrime group prior to MGM hack
  3. The Register: Caesars breach notification details
  4. Scripps News: Five defendants charged in connection with 2023 MGM, Caesars cyberattacks