CASE DOSSIER settled

Caesars Entertainment Scattered Spider Extortion ($15M Ransom)

Docket: SEC-8K-0000858339-23-000043 Court: U.S. Securities and Exchange Commission EDGAR Opened: 2023-09-07 Sector: Hospitality & Entertainment

Key Facts

Status
SETTLED
Legal disposition
Loss Amount
$15.0 million
Direct ransom payment transferred to cyber extortionists.
Techniques
2
Verified mappings
Defendants
0
Named in charges
  • Legal Status: SETTLED in U.S. Securities and Exchange Commission EDGAR.
  • Primary Target Sector: Hospitality & Entertainment.
  • Documented Financial Loss: $15.0 million.
  • 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Sophisticated vishing and social engineering intrusion by the Scattered Spider syndicate targeting an outsourced IT helpdesk servicing Caesars Entertainment, culminating in loyalty database exfiltration and approximately $15 million in cryptocurrency extortion paid to avert public release, disclosed in SEC Form 8-K Item 1.05.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Voice phishing (vishing) phone calls targeting an outsourced IT helpdesk servicing Caesars Entertainment, posing as employees to reset multi-factor authentication tokens.

Operational & Financial Fallout

Loyalty database exfiltrated, leading to approximately $15 million in cryptocurrency extortion paid to prevent public data release, disclosed under SEC Form 8-K Item 1.05.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: SETTLED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Voice phishing (vishing) phone calls targeting an outsourced IT helpdesk servicing Caesars Entertainment, posing as employees to reset multi-factor authentication tokens.

Adversary Kill Chain Flow

5 Documented Phases
1
Initial Social Engineering Outsourced Helpdesk Vishing Call
MITRE ATT&CK T1566.004 →

Scattered Spider operatives called an outsourced third-party service provider helpdesk, social engineering technicians into resetting user MFA credentials.

Artifacts & Tooling: Voice call spoofing MFA reset verification bypass
2
Identity Takeover Single Sign-On (SSO) Portal Access
MITRE ATT&CK T1078 →

Armed with newly assigned MFA tokens, attackers authenticated to corporate identity providers and traversed cloud business applications.

Artifacts & Tooling: Okta session hijacking Valid Azure AD credentials
3
Data Exfiltration Loyalty Database Extraction
MITRE ATT&CK T1567 →

Operatives located and downloaded database extracts containing customer names, driver license numbers, and Social Security numbers.

Artifacts & Tooling: Database export queries Encrypted cloud upload
4
Extortion Demand Dark Web Extortion Threat
MITRE ATT&CK T1651 →

Adversaries contacted Caesars executive leadership demanding cryptocurrency ransom, threatening to auction customer records on dark web forums.

Artifacts & Tooling: Telegram extortion communications Data proof samples
5
Extortion Settlement $15 Million Ransom Payment & SEC 8-K Filing
MITRE ATT&CK T1078 →

Caesars paid approximately $15 million in ransom to avert public data publication and filed Form 8-K Item 1.05 disclosing the event.

Artifacts & Tooling: SEC Form 8-K disclosure Cryptocurrency transaction
Real-World Blast Radius & Operational Fallout

Loyalty database exfiltrated, leading to approximately $15 million in cryptocurrency extortion paid to prevent public data release, disclosed under SEC Form 8-K Item 1.05.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce strict out-of-band cryptographic or biometric verification before helpdesk staff reset MFA tokens.
✓ Require phishing-resistant FIDO2 hardware security keys for all internal and vendor access.
✓ Deploy identity threat detection tools to identify unusual helpdesk password resets followed by immediate bulk data queries.
✓ Establish clear executive policies and legal playbooks regarding ransomware extortion decisions.

Procedural & Incident Timeline

2023-08-27 incident

Scattered Spider social engineers helpdesk to compromise Caesars contractor credentials.

2023-09-14 disclosure

Caesars submits SEC Form 8-K Item 1.05 disclosing data theft from its customer loyalty database.

2023-09-15 extortion

Reports confirm Caesars paid approximately $15 million in ransom to prevent customer records leak.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1566.004
"Operatives placed voice calls (vishing) to an outsourced vendor IT helpdesk, posing as employee personnel to reset multi-factor authentication credentials." CISA Advisory AA23-320A: Scattered Spider reviewed
T1078 Valid Accounts
Defense Evasion
"Adversaries utilized the newly minted MFA tokens to access Single Sign-On (SSO) portals and navigate corporate cloud environments." Caesars Form 8-K Item 1.05 Filing reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, Caesars Entertainment Scattered Spider Extortion ($15M Ransom), No. SEC-8K-0000858339-23-000043 (U.S. Securities and Exchange Commission EDGAR 2023), https://cybercaselibrary.com/cases/caesars-entertainment-scattered-spider/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/caesars-entertainment-scattered-spider" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>