Caesars Entertainment Scattered Spider Extortion ($15M Ransom)
Key Facts
- Legal Status: SETTLED in U.S. Securities and Exchange Commission EDGAR.
- Primary Target Sector: Hospitality & Entertainment.
- Documented Financial Loss: $15.0 million.
- 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Voice phishing (vishing) phone calls targeting an outsourced IT helpdesk servicing Caesars Entertainment, posing as employees to reset multi-factor authentication tokens.
Operational & Financial Fallout
Loyalty database exfiltrated, leading to approximately $15 million in cryptocurrency extortion paid to prevent public data release, disclosed under SEC Form 8-K Item 1.05.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Voice phishing (vishing) phone calls targeting an outsourced IT helpdesk servicing Caesars Entertainment, posing as employees to reset multi-factor authentication tokens.
Adversary Kill Chain Flow
5 Documented PhasesScattered Spider operatives called an outsourced third-party service provider helpdesk, social engineering technicians into resetting user MFA credentials.
Armed with newly assigned MFA tokens, attackers authenticated to corporate identity providers and traversed cloud business applications.
Operatives located and downloaded database extracts containing customer names, driver license numbers, and Social Security numbers.
Adversaries contacted Caesars executive leadership demanding cryptocurrency ransom, threatening to auction customer records on dark web forums.
Caesars paid approximately $15 million in ransom to avert public data publication and filed Form 8-K Item 1.05 disclosing the event.
Loyalty database exfiltrated, leading to approximately $15 million in cryptocurrency extortion paid to prevent public data release, disclosed under SEC Form 8-K Item 1.05.
Procedural & Incident Timeline
Scattered Spider social engineers helpdesk to compromise Caesars contractor credentials.
Caesars submits SEC Form 8-K Item 1.05 disclosing data theft from its customer loyalty database.
Reports confirm Caesars paid approximately $15 million in ransom to prevent customer records leak.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1566.004 | "Operatives placed voice calls (vishing) to an outsourced vendor IT helpdesk, posing as employee personnel to reset multi-factor authentication credentials." | CISA Advisory AA23-320A: Scattered Spider | reviewed | |
| T1078 | Valid Accounts Defense Evasion | "Adversaries utilized the newly minted MFA tokens to access Single Sign-On (SSO) portals and navigate corporate cloud environments." | Caesars Form 8-K Item 1.05 Filing | reviewed |