Case Library / Help-Desk & MFA Manipulation / Caesars Entertainment Vendor Social Engineering Breach (2023)

Caesars Entertainment Vendor Social Engineering Breach (2023)

Attackers later attributed to Scattered Spider (a group representative initially denied involvement) social-engineered Caesars Entertainment's outsourced IT support vendor, since identified in litigation as Coforge, into resetting credentials, stole the Caesars Rewards loyalty database (SSNs and driver's license numbers), and Caesars reportedly paid roughly $15 million to keep the data private. It was disclosed in an SEC 8-K days before the parallel MGM Resorts breach by the same actor.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

In August 2023, attackers later attributed to Scattered Spider (tracked as UNC3944) breached Caesars Entertainment by social-engineering an outsourced IT support vendor rather than attacking Caesars directly. Later Nevada federal court filings place the initial intrusion on or about August 18, 2023; Caesars' state breach notices say it identified suspicious activity on August 19, 2023. The attackers used vendor-granted access to reach Caesars' authentication environment and exfiltrated a copy of the Caesars Rewards loyalty-program database, which included driver's license numbers and/or Social Security numbers for a significant number of members. Caesars disclosed the incident in an SEC Form 8-K (Item 8.01) filed September 14, 2023, referencing September 7, 2023 as the date it determined the scope of what was taken. Bloomberg, the Wall Street Journal, and Reuters separately reported that Caesars paid roughly $15 million in cryptocurrency to the attackers, down from an initial $30 million demand, to prevent the stolen data from being published, a figure not stated in Caesars' own SEC filing. Notably, on the same day the 8-K was filed, a person claiming to speak for Scattered Spider publicly denied any role in the Caesars attack to multiple outlets while claiming the MGM breach; attribution to Scattered Spider for Caesars nonetheless firmed up through Bloomberg's sourcing and, later, through Caesars' own 2024 litigation filings, which name Scattered Spider as the attacker. A subsequent, related federal lawsuit identifies the previously unnamed vendor as Coforge, Inc./Coforge, Ltd. The breach happened in the same window as, and is now attributed to the same threat actor as, the MGM Resorts breach disclosed the following week, giving the industry a paired real-world case study of paying (Caesars) versus refusing to pay (MGM) a ransom demand.

How the Attack Worked

Rather than phishing Caesars employees directly, attackers targeted a third-party IT support/help-desk vendor that held privileged access to Caesars' identity and authentication systems. According to later Nevada federal court filings and multiple outlets (Reuters, Bloomberg, TechTarget), the actor placed a phone call to the vendor, convincingly impersonated a legitimate Caesars employee, and persuaded vendor support staff to reset credentials/MFA. That reset handed the attacker authenticated access into Caesars' environment (widely reported, though outside the 8-K, as reaching Caesars' Okta-connected single sign-on; Okta itself later confirmed Caesars and MGM were among affected customers). From that foothold the actor moved laterally and, over a window of roughly five days, located and exfiltrated the Caesars Rewards loyalty-program database. Court filings give slightly differing detail on that window: the Caesars class-action background recitation states Caesars flagged suspicious activity the same day the intrusion began, with the data downloaded five days later, while the separate complaint against vendor Coforge describes the attackers operating undetected for five days before exfiltrating; either way, detection did not stop the exfiltration before it completed. Caesars stated it found no evidence that member passwords/PINs, bank account information, or payment-card data were taken, only loyalty-database contents including driver's license numbers and/or Social Security numbers for "a significant number" of members. Attribution note: on September 14, 2023, a person claiming to represent Scattered Spider told TechCrunch, CyberScoop, and Business Insider that the group had "no involvement" in the Caesars attack, even while affirmatively claiming that week's parallel MGM Resorts breach. Bloomberg's contemporaneous reporting (citing four people familiar with the matter) nonetheless attributed both intrusions to Scattered Spider, and the attribution firmed up over time; see threat_actor for how Caesars itself later adopted it in litigation. A related, since-filed Nevada federal case identifies the previously unnamed vendor as Coforge, Inc./Coforge, Ltd. (formerly NIIT Technologies), which operated Caesars' IT service desk under a statement of work covering password resets and MFA management; Caesars' own 8-K left the vendor unnamed.

The Lure & the Tell

The lure was not aimed at a Caesars employee but at the outsourced vendor's help-desk staff: a caller convincingly impersonated an internal Caesars employee and exploited the vendor's phone-based, knowledge-based identity-verification workflow (built around employee ID, manager name, or other easily obtained personal/employment details) to get credentials/MFA reset. Vendor agents had no reliable way to distinguish the impersonator from a genuine employee using only that verification method, illustrating how supply-chain help-desk trust is an exploitable seam even when the target company's own staff and systems are otherwise well defended. There was no phishing email, malicious link, or QR code involved; the entire initial-access vector was a convincing phone conversation.

Outcome

Caesars reportedly paid approximately $15 million (down from a $30 million demand) to prevent publication of the stolen data; the 8-K noted Caesars could not guarantee the data was actually deleted by the attacker. Caesars sent breach notifications to state attorneys general (e.g., Iowa, Maryland) and was named in a consolidated class action in the U.S. District Court for the District of Nevada (motion to dismiss denied in part per an August 15, 2025 order); a related class action against the vendor, Coforge, Inc./Coforge, Ltd. (Case No. 2:25-cv-00736-JAD-DJA), was consolidated into the lead Caesars case (2:23-cv-01447-ART-BNW) in mid-2025. On November 20, 2024, the U.S. Attorney's Office for the Central District of California charged five alleged Scattered Spider members (Ahmed Hossam Eldin Elbadawy, Noah Michael Urban, Evans Onyeaka Osiebo, Joel Martin Evans, and Tyler Robert Buchanan) with wire-fraud conspiracy and aggravated identity theft tied to a broader phishing-text/credential-harvesting campaign; that DOJ release describes the group's general methodology but does not name Caesars or MGM as victims, so no arrest has been publicly and officially tied to this specific intrusion.

Why It Matters

Caesars is one of the clearest documented cases where the exploited control was a company's vendor/help-desk trust relationship rather than a gap in the target company's own employee training, meaning even organizations with strong internal security awareness remain exposed through outsourced IT support with reset privileges. Paired with the MGM Resorts breach (same actor, same month, opposite pay/no-pay decisions and outcomes), it became the reference case boards and CISOs cite when weighing ransom payment trade-offs. It also underscored that delegated administrative/reset capability over an identity provider (e.g., Okta) is a high-value, frequently under-governed attack surface that extends the organization's attack surface through every vendor holding it. The episode is also a useful caution on attribution: a threat actor's own contemporaneous denial does not settle the question, and even the victim's later adversarial-litigation filings can be the strongest attribution evidence available.

Defenses

Post-incident recommendations centered on hardening identity-reset workflows: require strong, hard-to-phish verification (manager approval, video/in-person check, phishing-resistant MFA re-enrollment) before any password/MFA reset, at both internal help desks and any outsourced IT support vendor holding reset privileges; treat vendor access to identity platforms (e.g., Okta admin capability) as high-privilege access requiring the same monitoring/controls as internal domain-admin accounts; log and alert on resets followed by logins from new devices/locations; extend vendor security assessments to specifically test help-desk social-engineering resistance rather than general security posture only. Caesars stated in its 8-K that it has "also taken steps to ensure that the specific outsourced IT support vendor involved in this matter has implemented corrective measures to protect against future attacks."

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance: Scattered Spider is documented (per contemporaneous reporting and the group's established pattern in the parallel MGM intrusion) as researching a real Caesars employee using LinkedIn, other professional-networking sources, and commercially available personal data, building enough of a profile (name, role, and identifying details) to pass a phone-based identity check.
Countering Stage 1: Employee-facing OSINT exposure (LinkedIn roles, org charts, employment details) is very hard to eliminate at enterprise scale; the realistic control assumes attackers already have this and hardens the verification process it gets used against, rather than trying to hide it.
2
Vendor and pretext selection: Court filings indicate the attackers targeted Coforge, the outsourced IT/help-desk vendor holding Caesars' password-reset and MFA-management responsibilities under its service-desk contract, rather than Caesars directly, and prepared a routine-sounding credential-reset request as the pretext.
Countering Stage 2: Extend vendor security assessments to specifically test outsourced help-desk staff's resistance to social engineering, not just the vendor's general security posture, and contractually require the same reset-verification standard from vendors that the company would apply internally.
3
Vishing call to the vendor help desk: The attacker called Coforge's service desk by phone, impersonating the identified Caesars employee and using the harvested personal details to pass the vendor's knowledge-based identity-verification workflow.
Countering Stage 3: Train help-desk staff (internal and vendor) specifically on vishing pretexts so a plausible, routine-sounding reset request does not get an easier pass than an obviously suspicious one.
4
Credential/MFA reset: Coforge staff reset the impersonated employee's password and/or MFA without independently verifying the caller's identity, handing the attacker a fully authenticated credential with no need to defeat MFA technically.
Countering Stage 4: Require a scripted, non-negotiable identity-verification procedure for any phone-based credential/MFA reset, such as manager callback to a number on file, video check, or phishing-resistant re-enrollment, at both internal help desks and any vendor holding reset privileges. This is the single control point where the entire intrusion could most plausibly have been stopped.
5
Privileged access to the identity provider: The reset credential was used to reach Caesars' Okta-connected single sign-on environment, reportedly (per Okta's own later customer disclosure) at a privilege level sufficient to affect broader identity infrastructure.
Countering Stage 5: Treat vendor-held administrative access to identity providers (e.g., Okta) as high-privilege access requiring the same monitoring and hardware-backed MFA controls as internal domain-admin accounts, with alerting on privilege changes and new-device logins immediately following a reset.
6
Lateral movement and data location: From that foothold the actor moved through Caesars' environment over a period court filings put at roughly five days, locating the Caesars Rewards loyalty-program database among other systems.
Countering Stage 6: Network and identity segmentation limiting how far a single compromised identity-provider session can reach, plus monitoring for anomalous lateral movement following an MFA reset.
7
Data exfiltration: The attacker copied out the loyalty-program database, including driver's license numbers and/or Social Security numbers for a significant number of members, before Caesars' containment measures stopped further access.
Countering Stage 7: Data-loss-prevention monitoring for large or unusual outbound transfers from sensitive databases, and minimizing retained legacy loyalty-program PII (e.g., full SSNs/driver's license numbers), reduces what is available to steal even after a breach starts.
8
Extortion and payout: The actor threatened to publish the stolen data and demanded an initial $30 million; Caesars negotiated and reportedly paid roughly $15 million in cryptocurrency to prevent publication, per Bloomberg/WSJ/Reuters reporting (not confirmed by amount in Caesars' own SEC filing).
Countering Stage 8: There is no reliable technical control once data has already been exfiltrated and extortion begins; the realistic response shifts to incident-response and legal preparation (law-enforcement engagement, credit-monitoring offers, and a pre-decided organizational stance on ransom payment) rather than a control that prevents the demand itself, with Stage 4 remaining the point of highest leverage to have avoided reaching this stage.
Quick Facts
Victim
Caesars Entertainment, Inc.
Location
United States. Caesars Entertainment, Inc. (headquartered Reno, Nevada); affected members nationwide (state breach notifications filed with, among others, Iowa and Maryland AGs); the outsourced IT vendor, since identified in litigation as Coforge, staffed a service desk in Las Vegas, Nevada
Date
Intrusion on or about August 18, 2023 (per later Nevada federal court filings); Caesars identified suspicious activity August 19, 2023 (per state breach notices) / August 18, 2023 per the court's later background recitation; publicly disclosed via SEC Form 8-K filed September 14, 2023, referencing a September 7, 2023 determination date
Impact
Widely reported (Bloomberg/WSJ/Reuters) that Caesars paid approximately $15 million in cryptocurrency, reduced from an initial $30 million demand, to prevent publication of stolen loyalty-program data. This figure is NOT stated in Caesars' SEC 8-K itself: the filing discusses steps taken to have the actor delete the data (implying payment/negotiation) but does not disclose an amount, so treat $15M as reported/attributed rather than company-confirmed in the primary filing (Caesars' own 2024 motion to dismiss likewise characterizes the $15M figure as a plaintiffs' allegation, not a Caesars admission). Additional undisclosed costs from incident response, legal fees, state AG notifications, and a consolidated federal class action in the District of Nevada.
Status
Confirmed
Case Type
Real-World Incident
Sector
Consumer / General Public, Hospitality, Gaming & Travel
Threat Actor
Organized Crime
Related

Related Cases

Clorox / Cognizant Help-Desk Pretexting Breach

A caller posing as two different Clorox employees talked Cognizant's outsourced IT help desk into resetting their passwords and MFA…

Incident 2023Read →

MGM Resorts Help-Desk Vishing Breach (Scattered Spider, 2023)

A roughly ten-minute phone call impersonating an MGM employee to the IT help desk let Scattered Spider reset MFA, seize…

Incident 2023Read →

Uber 2022 Breach: MFA Push-Bombing and IT-Support Impersonation of a Contractor

A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…

Incident 2022Read →