{
  "id": "case-caesars-scattered-spider",
  "slug": "caesars-entertainment-scattered-spider",
  "title": "Caesars Entertainment Scattered Spider Extortion ($15M Ransom)",
  "summary": "Sophisticated vishing and social engineering intrusion by the Scattered Spider syndicate targeting an outsourced IT helpdesk servicing Caesars Entertainment, culminating in loyalty database exfiltration and approximately $15 million in cryptocurrency extortion paid to avert public release, disclosed in SEC Form 8-K Item 1.05.",
  "case_number": "SEC-8K-0000858339-23-000043",
  "court": "U.S. Securities and Exchange Commission EDGAR",
  "district": "District of Nevada",
  "country": "United States",
  "opened_at": "2023-09-07",
  "status": "settled",
  "victim_sector": "Hospitality & Entertainment",
  "victim_country": "United States",
  "loss_amount_usd": 15000000,
  "loss_amount_note": "Direct ransom payment transferred to cyber extortionists.",
  "first_seen_at": "2023-08-27T00:00:00Z",
  "last_updated_at": "2026-10-06T10:00:00Z",
  "actor_slug": "scattered-spider",
  "defendant_slugs": [],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1566.004",
      "evidence_excerpt": "Operatives placed voice calls (vishing) to an outsourced vendor IT helpdesk, posing as employee personnel to reset multi-factor authentication credentials.",
      "evidence_locator": "CISA Advisory AA23-320A: Scattered Spider",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA23-320A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a"
    },
    {
      "technique_id": "T1078",
      "evidence_excerpt": "Adversaries utilized the newly minted MFA tokens to access Single Sign-On (SSO) portals and navigate corporate cloud environments.",
      "evidence_locator": "Caesars Form 8-K Item 1.05 Filing",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "SEC Form 8-K Caesars Entertainment",
      "source_url": "https://www.sec.gov",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    }
  ],
  "events": [
    {
      "event_type": "incident",
      "event_date": "2023-08-27",
      "description": "Scattered Spider social engineers helpdesk to compromise Caesars contractor credentials."
    },
    {
      "event_type": "disclosure",
      "event_date": "2023-09-14",
      "description": "Caesars submits SEC Form 8-K Item 1.05 disclosing data theft from its customer loyalty database."
    },
    {
      "event_type": "extortion",
      "event_date": "2023-09-15",
      "description": "Reports confirm Caesars paid approximately $15 million in ransom to prevent customer records leak."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Voice phishing (vishing) phone calls targeting an outsourced IT helpdesk servicing Caesars Entertainment, posing as employees to reset multi-factor authentication tokens.",
    "blast_radius": "Loyalty database exfiltrated, leading to approximately $15 million in cryptocurrency extortion paid to prevent public data release, disclosed under SEC Form 8-K Item 1.05.",
    "kill_chain": [
      {
        "phase": "Initial Social Engineering",
        "title": "Outsourced Helpdesk Vishing Call",
        "description": "Scattered Spider operatives called an outsourced third-party service provider helpdesk, social engineering technicians into resetting user MFA credentials.",
        "technical_artifacts": [
          "Voice call spoofing",
          "MFA reset verification bypass"
        ],
        "mitre_technique_id": "T1566.004"
      },
      {
        "phase": "Identity Takeover",
        "title": "Single Sign-On (SSO) Portal Access",
        "description": "Armed with newly assigned MFA tokens, attackers authenticated to corporate identity providers and traversed cloud business applications.",
        "technical_artifacts": [
          "Okta session hijacking",
          "Valid Azure AD credentials"
        ],
        "mitre_technique_id": "T1078"
      },
      {
        "phase": "Data Exfiltration",
        "title": "Loyalty Database Extraction",
        "description": "Operatives located and downloaded database extracts containing customer names, driver license numbers, and Social Security numbers.",
        "technical_artifacts": [
          "Database export queries",
          "Encrypted cloud upload"
        ],
        "mitre_technique_id": "T1567"
      },
      {
        "phase": "Extortion Demand",
        "title": "Dark Web Extortion Threat",
        "description": "Adversaries contacted Caesars executive leadership demanding cryptocurrency ransom, threatening to auction customer records on dark web forums.",
        "technical_artifacts": [
          "Telegram extortion communications",
          "Data proof samples"
        ],
        "mitre_technique_id": "T1651"
      },
      {
        "phase": "Extortion Settlement",
        "title": "$15 Million Ransom Payment & SEC 8-K Filing",
        "description": "Caesars paid approximately $15 million in ransom to avert public data publication and filed Form 8-K Item 1.05 disclosing the event.",
        "technical_artifacts": [
          "SEC Form 8-K disclosure",
          "Cryptocurrency transaction"
        ],
        "mitre_technique_id": "T1078"
      }
    ],
    "defensive_takeaways": [
      "Enforce strict out-of-band cryptographic or biometric verification before helpdesk staff reset MFA tokens.",
      "Require phishing-resistant FIDO2 hardware security keys for all internal and vendor access.",
      "Deploy identity threat detection tools to identify unusual helpdesk password resets followed by immediate bulk data queries.",
      "Establish clear executive policies and legal playbooks regarding ransomware extortion decisions."
    ]
  }
}