The Caesars Entertainment breach: Scattered Spider social-engineered an IT help desk, stealing a loyalty database and prompting a $15M ransom in 2023.
Social Engineering Examples·14 sources
In August 2023, attackers later attributed to Scattered Spider (tracked as UNC3944) breached Caesars Entertainment by social-engineering an outsourced IT support vendor rather than attacking Caesars directly. Later Nevada federal court filings place the initial intrusion on or about August 18, 2023; Caesars' state breach notices say it identified suspicious activity on August 19, 2023. The attackers used vendor-granted access to reach Caesars' authentication environment and exfiltrated a copy of the Caesars Rewards loyalty-program database, which included driver's license numbers and/or Social Security numbers for a significant number of members.
Caesars disclosed the incident in an SEC Form 8-K (Item 8.01) filed September 14, 2023, referencing September 7, 2023 as the date it determined the scope of what was taken. Bloomberg, the Wall Street Journal, and Reuters separately reported that Caesars paid roughly $15 million in cryptocurrency to the attackers, down from an initial $30 million demand, to prevent the stolen data from being published, a figure not stated in Caesars' own SEC filing.
Notably, on the same day the 8-K was filed, a person claiming to speak for Scattered Spider publicly denied any role in the Caesars attack to multiple outlets while claiming the MGM breach; attribution to Scattered Spider for Caesars nonetheless firmed up through Bloomberg's sourcing and, later, through Caesars' own 2024 litigation filings, which name Scattered Spider as the attacker.
A subsequent, related federal lawsuit identifies the previously unnamed vendor as Coforge, Inc./Coforge, Ltd. The breach happened in the same window as, and is now attributed to the same threat actor as, the MGM Resorts breach disclosed the following week, giving the industry a paired real-world case study of paying (Caesars) versus refusing to pay (MGM) a ransom demand.
Rather than phishing Caesars employees directly, attackers targeted a third-party IT support/help-desk vendor that held privileged access to Caesars' identity and authentication systems. According to later Nevada federal court filings and multiple outlets (Reuters, Bloomberg, TechTarget), the actor placed a phone call to the vendor, convincingly impersonated a legitimate Caesars employee, and persuaded vendor support staff to reset credentials/MFA.
That reset handed the attacker authenticated access into Caesars' environment (widely reported, though outside the 8-K, as reaching Caesars' Okta-connected single sign-on; Okta itself later confirmed Caesars and MGM were among affected customers). From that foothold the actor moved laterally and, over a window of roughly five days, located and exfiltrated the Caesars Rewards loyalty-program database.
Court filings give slightly differing detail on that window: the Caesars class-action background recitation states Caesars flagged suspicious activity the same day the intrusion began, with the data downloaded five days later, while the separate complaint against vendor Coforge describes the attackers operating undetected for five days before exfiltrating; either way, detection did not stop the exfiltration before it completed.
Caesars stated it found no evidence that member passwords/PINs, bank account information, or payment-card data were taken, only loyalty-database contents including driver's license numbers and/or Social Security numbers for "a significant number" of members. Attribution note: on September 14, 2023, a person claiming to represent Scattered Spider told TechCrunch, CyberScoop, and Business Insider that the group had "no involvement" in the Caesars attack, even while affirmatively claiming that week's parallel MGM Resorts breach.
Bloomberg's contemporaneous reporting (citing four people familiar with the matter) nonetheless attributed both intrusions to Scattered Spider, and the attribution firmed up over time; see threat_actor for how Caesars itself later adopted it in litigation. A related, since-filed Nevada federal case identifies the previously unnamed vendor as Coforge, Inc./Coforge, Ltd. (formerly NIIT Technologies), which operated Caesars' IT service desk under a statement of work covering password resets and MFA management; Caesars' own 8-K left the vendor unnamed.
The lure was not aimed at a Caesars employee but at the outsourced vendor's help-desk staff: a caller convincingly impersonated an internal Caesars employee and exploited the vendor's phone-based, knowledge-based identity-verification workflow (built around employee ID, manager name, or other easily obtained personal/employment details) to get credentials/MFA reset.
Vendor agents had no reliable way to distinguish the impersonator from a genuine employee using only that verification method, illustrating how supply-chain help-desk trust is an exploitable seam even when the target company's own staff and systems are otherwise well defended. There was no phishing email, malicious link, or QR code involved; the entire initial-access vector was a convincing phone conversation.
Caesars reportedly paid approximately $15 million (down from a $30 million demand) to prevent publication of the stolen data; the 8-K noted Caesars could not guarantee the data was actually deleted by the attacker. Caesars sent breach notifications to state attorneys general (e.g., Iowa, Maryland) and was named in a consolidated class action in the U.S. District Court for the District of Nevada (motion to dismiss denied in part per an August 15, 2025 order); a related class action against the vendor, Coforge, Inc./Coforge, Ltd. (Case No. 2:25-cv-00736-JAD-DJA), was consolidated into the lead Caesars case (2:23-cv-01447-ART-BNW) in mid-2025. On November 20, 2024, the U.S. Attorney's Office for the Central District of California charged five alleged Scattered Spider members (Ahmed Hossam Eldin Elbadawy, Noah Michael Urban, Evans Onyeaka Osiebo, Joel Martin Evans, and Tyler Robert Buchanan) with wire-fraud conspiracy and aggravated identity theft tied to a broader phishing-text/credential-harvesting campaign; that DOJ release describes the group's general methodology but does not name Caesars or MGM as victims, so no arrest has been publicly and officially tied to this specific intrusion.
Regulatory disclosure: Caesars Entertainment disclosed the breach in a Form 8-K filing with the SEC. Source: Caesars Entertainment investor relations, Form 8-K.
Caesars is one of the clearest documented cases where the exploited control was a company's vendor/help-desk trust relationship rather than a gap in the target company's own employee training, meaning even organizations with strong internal security awareness remain exposed through outsourced IT support with reset privileges. Paired with the MGM Resorts breach (same actor, same month, opposite pay/no-pay decisions and outcomes), it became the reference case boards and CISOs cite when weighing ransom payment trade-offs.
It also underscored that delegated administrative/reset capability over an identity provider (e.g., Okta) is a high-value, frequently under-governed attack surface that extends the organization's attack surface through every vendor holding it. The episode is also a useful caution on attribution: a threat actor's own contemporaneous denial does not settle the question, and even the victim's later adversarial-litigation filings can be the strongest attribution evidence available.
Post-incident recommendations centered on hardening identity-reset workflows: require strong, hard-to-phish verification (manager approval, video/in-person check, phishing-resistant MFA re-enrollment) before any password/MFA reset, at both internal help desks and any outsourced IT support vendor holding reset privileges; treat vendor access to identity platforms (e.g., Okta admin capability) as high-privilege access requiring the same monitoring/controls as internal domain-admin accounts; log and alert on resets followed by logins from new devices/locations; extend vendor security assessments to specifically test help-desk social-engineering resistance rather than general security posture only.
Caesars stated in its 8-K that it has "also taken steps to ensure that the specific outsourced IT support vendor involved in this matter has implemented corrective measures to protect against future attacks."
Social Engineering Examples. “Caesars Entertainment Vendor Social Engineering Breach (2023)”. Accessed 19 September 2026. https://socialengineeringexamples.com/caesars-entertainment-vendor-social-engineering-2023
Scattered Spider is documented (per contemporaneous reporting and the group's established pattern in the parallel MGM intrusion) as researching a real Caesars employee using LinkedIn, other professional-networking sources, and commercially available personal data, building enough of a profile (name, role, and identifying details) to pass a phone-based identity check.
Employee-facing OSINT exposure (LinkedIn roles, org charts, employment details) is very hard to eliminate at enterprise scale; the realistic control assumes attackers already have this and hardens the verification process it gets used against, rather than trying to hide it.
Court filings indicate the attackers targeted Coforge, the outsourced IT/help-desk vendor holding Caesars' password-reset and MFA-management responsibilities under its service-desk contract, rather than Caesars directly, and prepared a routine-sounding credential-reset request as the pretext.
Extend vendor security assessments to specifically test outsourced help-desk staff's resistance to social engineering, not just the vendor's general security posture, and contractually require the same reset-verification standard from vendors that the company would apply internally.
The attacker called Coforge's service desk by phone, impersonating the identified Caesars employee and using the harvested personal details to pass the vendor's knowledge-based identity-verification workflow.
Train help-desk staff (internal and vendor) specifically on vishing pretexts so a plausible, routine-sounding reset request does not get an easier pass than an obviously suspicious one.
Coforge staff reset the impersonated employee's password and/or MFA without independently verifying the caller's identity, handing the attacker a fully authenticated credential with no need to defeat MFA technically.
Require a scripted, non-negotiable identity-verification procedure for any phone-based credential/MFA reset, such as manager callback to a number on file, video check, or phishing-resistant re-enrollment, at both internal help desks and any vendor holding reset privileges. This is the single control point where the entire intrusion could most plausibly have been stopped.
The reset credential was used to reach Caesars' Okta-connected single sign-on environment, reportedly (per Okta's own later customer disclosure) at a privilege level sufficient to affect broader identity infrastructure.
Treat vendor-held administrative access to identity providers (e.g., Okta) as high-privilege access requiring the same monitoring and hardware-backed MFA controls as internal domain-admin accounts, with alerting on privilege changes and new-device logins immediately following a reset.
From that foothold the actor moved through Caesars' environment over a period court filings put at roughly five days, locating the Caesars Rewards loyalty-program database among other systems.
Network and identity segmentation limiting how far a single compromised identity-provider session can reach, plus monitoring for anomalous lateral movement following an MFA reset.
The attacker copied out the loyalty-program database, including driver's license numbers and/or Social Security numbers for a significant number of members, before Caesars' containment measures stopped further access.
Data-loss-prevention monitoring for large or unusual outbound transfers from sensitive databases, and minimizing retained legacy loyalty-program PII (e.g., full SSNs/driver's license numbers), reduces what is available to steal even after a breach starts.
The actor threatened to publish the stolen data and demanded an initial $30 million; Caesars negotiated and reportedly paid roughly $15 million in cryptocurrency to prevent publication, per Bloomberg/WSJ/Reuters reporting (not confirmed by amount in Caesars' own SEC filing).
There is no reliable technical control once data has already been exfiltrated and extortion begins; the realistic response shifts to incident-response and legal preparation (law-enforcement engagement, credit-monitoring offers, and a pre-decided organizational stance on ransom payment) rather than a control that prevents the demand itself, with Stage 4 remaining the point of highest leverage to have avoided reaching this stage.
Browse by what this case has in common with others in the library.
A caller posing as two different Clorox employees talked Cognizant's outsourced IT help desk into resetting their passwords and MFA…
Scattered Spider's ten-minute vishing call to MGM's help desk reset MFA and seized identity systems, an incident Moody's called credit-negative.
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset.
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
A Singaporean finance professional in her 50s lost S$1.2 million.
A Taiwan-linked money courier was caught in an Austin bank sting while collecting part of the $1.4 million a victim…
In June 2025 the DOJ filed a civil forfeiture complaint against more than $225.3M in Tether (USDT) traced to a…
A victim searching for the AnyDesk remote-access tool hit a typosquatted site with a fake Cloudflare Turnstile.
DOJ alleges Ghanaian twins Jamal and Kamal Abubakari and U.S.-based Amanda Opoku-Boachie ran an AI-video-enabled romance fraud ring that used…
DOJ/FTC alleged that Citizens Disability and subsidiary CD Media made 109 million-plus illegal telemarketing calls.
Chinese state-linked hackers used spear-phishing links and an unpatched Internet Explorer zero-day to breach Google, Adobe.
A mass SMS phishing campaign impersonating U.S. toll agencies spoofed 'unpaid toll' notices, drawing 2,000+ FBI complaints within weeks.
eSentire's Threat Response Unit blocked 10 separate attacks across six unnamed law firms in Jan-Feb 2023, foiling two parallel campaigns.
Between 2006 and 2008 the FTC sued 16 data-broker and private-investigation defendants who pretexted telecom carriers.
Attackers phoned Twitter employees posing as IT help desk, harvested VPN credentials.
Air Canada admitted in a sworn Ontario Superior Court affidavit that it hired private investigators who twice took trash from…
eSentire's Threat Response Unit blocked 10 separate attacks across six unnamed law firms in Jan-Feb 2023, foiling two parallel campaigns.
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
A 16-member Colombian crime ring called and WhatsApp-messaged bank customers posing as fraud-prevention officers.
An interstate Indian gang used AI-generated "eye-blink" deepfake videos made from stolen social-media photos to fool Aadhaar's facial-liveness e-KYC.
Two Quebec fraudsters acting as courier and driver for an AI-voice-cloned "grandchild in crisis" vishing scheme that defrauded Saskatchewan seniors.
Fraudsters posing as Tecnimont's group CEO, other executives, and a fictitious Swiss lawyer used spoofed emails and a staged series…