Attackers later attributed to Scattered Spider (a group representative initially denied involvement) social-engineered Caesars Entertainment's outsourced IT support vendor, since identified in litigation as Coforge, into resetting credentials, stole the Caesars Rewards loyalty database (SSNs and driver's license numbers), and Caesars reportedly paid roughly $15 million to keep the data private. It was disclosed in an SEC 8-K days before the parallel MGM Resorts breach by the same actor.
Reviewed by the Social Engineering Examples team.
In August 2023, attackers later attributed to Scattered Spider (tracked as UNC3944) breached Caesars Entertainment by social-engineering an outsourced IT support vendor rather than attacking Caesars directly. Later Nevada federal court filings place the initial intrusion on or about August 18, 2023; Caesars' state breach notices say it identified suspicious activity on August 19, 2023. The attackers used vendor-granted access to reach Caesars' authentication environment and exfiltrated a copy of the Caesars Rewards loyalty-program database, which included driver's license numbers and/or Social Security numbers for a significant number of members. Caesars disclosed the incident in an SEC Form 8-K (Item 8.01) filed September 14, 2023, referencing September 7, 2023 as the date it determined the scope of what was taken. Bloomberg, the Wall Street Journal, and Reuters separately reported that Caesars paid roughly $15 million in cryptocurrency to the attackers, down from an initial $30 million demand, to prevent the stolen data from being published, a figure not stated in Caesars' own SEC filing. Notably, on the same day the 8-K was filed, a person claiming to speak for Scattered Spider publicly denied any role in the Caesars attack to multiple outlets while claiming the MGM breach; attribution to Scattered Spider for Caesars nonetheless firmed up through Bloomberg's sourcing and, later, through Caesars' own 2024 litigation filings, which name Scattered Spider as the attacker. A subsequent, related federal lawsuit identifies the previously unnamed vendor as Coforge, Inc./Coforge, Ltd. The breach happened in the same window as, and is now attributed to the same threat actor as, the MGM Resorts breach disclosed the following week, giving the industry a paired real-world case study of paying (Caesars) versus refusing to pay (MGM) a ransom demand.
Rather than phishing Caesars employees directly, attackers targeted a third-party IT support/help-desk vendor that held privileged access to Caesars' identity and authentication systems. According to later Nevada federal court filings and multiple outlets (Reuters, Bloomberg, TechTarget), the actor placed a phone call to the vendor, convincingly impersonated a legitimate Caesars employee, and persuaded vendor support staff to reset credentials/MFA. That reset handed the attacker authenticated access into Caesars' environment (widely reported, though outside the 8-K, as reaching Caesars' Okta-connected single sign-on; Okta itself later confirmed Caesars and MGM were among affected customers). From that foothold the actor moved laterally and, over a window of roughly five days, located and exfiltrated the Caesars Rewards loyalty-program database. Court filings give slightly differing detail on that window: the Caesars class-action background recitation states Caesars flagged suspicious activity the same day the intrusion began, with the data downloaded five days later, while the separate complaint against vendor Coforge describes the attackers operating undetected for five days before exfiltrating; either way, detection did not stop the exfiltration before it completed. Caesars stated it found no evidence that member passwords/PINs, bank account information, or payment-card data were taken, only loyalty-database contents including driver's license numbers and/or Social Security numbers for "a significant number" of members. Attribution note: on September 14, 2023, a person claiming to represent Scattered Spider told TechCrunch, CyberScoop, and Business Insider that the group had "no involvement" in the Caesars attack, even while affirmatively claiming that week's parallel MGM Resorts breach. Bloomberg's contemporaneous reporting (citing four people familiar with the matter) nonetheless attributed both intrusions to Scattered Spider, and the attribution firmed up over time; see threat_actor for how Caesars itself later adopted it in litigation. A related, since-filed Nevada federal case identifies the previously unnamed vendor as Coforge, Inc./Coforge, Ltd. (formerly NIIT Technologies), which operated Caesars' IT service desk under a statement of work covering password resets and MFA management; Caesars' own 8-K left the vendor unnamed.
The lure was not aimed at a Caesars employee but at the outsourced vendor's help-desk staff: a caller convincingly impersonated an internal Caesars employee and exploited the vendor's phone-based, knowledge-based identity-verification workflow (built around employee ID, manager name, or other easily obtained personal/employment details) to get credentials/MFA reset. Vendor agents had no reliable way to distinguish the impersonator from a genuine employee using only that verification method, illustrating how supply-chain help-desk trust is an exploitable seam even when the target company's own staff and systems are otherwise well defended. There was no phishing email, malicious link, or QR code involved; the entire initial-access vector was a convincing phone conversation.
Caesars reportedly paid approximately $15 million (down from a $30 million demand) to prevent publication of the stolen data; the 8-K noted Caesars could not guarantee the data was actually deleted by the attacker. Caesars sent breach notifications to state attorneys general (e.g., Iowa, Maryland) and was named in a consolidated class action in the U.S. District Court for the District of Nevada (motion to dismiss denied in part per an August 15, 2025 order); a related class action against the vendor, Coforge, Inc./Coforge, Ltd. (Case No. 2:25-cv-00736-JAD-DJA), was consolidated into the lead Caesars case (2:23-cv-01447-ART-BNW) in mid-2025. On November 20, 2024, the U.S. Attorney's Office for the Central District of California charged five alleged Scattered Spider members (Ahmed Hossam Eldin Elbadawy, Noah Michael Urban, Evans Onyeaka Osiebo, Joel Martin Evans, and Tyler Robert Buchanan) with wire-fraud conspiracy and aggravated identity theft tied to a broader phishing-text/credential-harvesting campaign; that DOJ release describes the group's general methodology but does not name Caesars or MGM as victims, so no arrest has been publicly and officially tied to this specific intrusion.
Caesars is one of the clearest documented cases where the exploited control was a company's vendor/help-desk trust relationship rather than a gap in the target company's own employee training, meaning even organizations with strong internal security awareness remain exposed through outsourced IT support with reset privileges. Paired with the MGM Resorts breach (same actor, same month, opposite pay/no-pay decisions and outcomes), it became the reference case boards and CISOs cite when weighing ransom payment trade-offs. It also underscored that delegated administrative/reset capability over an identity provider (e.g., Okta) is a high-value, frequently under-governed attack surface that extends the organization's attack surface through every vendor holding it. The episode is also a useful caution on attribution: a threat actor's own contemporaneous denial does not settle the question, and even the victim's later adversarial-litigation filings can be the strongest attribution evidence available.
Post-incident recommendations centered on hardening identity-reset workflows: require strong, hard-to-phish verification (manager approval, video/in-person check, phishing-resistant MFA re-enrollment) before any password/MFA reset, at both internal help desks and any outsourced IT support vendor holding reset privileges; treat vendor access to identity platforms (e.g., Okta admin capability) as high-privilege access requiring the same monitoring/controls as internal domain-admin accounts; log and alert on resets followed by logins from new devices/locations; extend vendor security assessments to specifically test help-desk social-engineering resistance rather than general security posture only. Caesars stated in its 8-K that it has "also taken steps to ensure that the specific outsourced IT support vendor involved in this matter has implemented corrective measures to protect against future attacks."
A caller posing as two different Clorox employees talked Cognizant's outsourced IT help desk into resetting their passwords and MFA…
A roughly ten-minute phone call impersonating an MGM employee to the IT help desk let Scattered Spider reset MFA, seize…
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…