Case ID
Caesars 2023: ~$15M paid to keep the lights on.
Days before the MGM outage made headlines, the same threat-actor ecosystem, Scattered Spider, breached Caesars Entertainment through a social-engineering attack on an outsourced IT support vendor. The attackers exfiltrated the Caesars Rewards loyalty database, containing driver's license numbers and Social Security numbers for a significant number of members. Caesars reportedly paid roughly $15 million, about half of a ~$30 million demand, and its customer-facing casino and online operations continued without disruption. Caesars took the opposite path from MGM, and the two responses became the definitive paired case study in the economics of paying versus refusing a ransom.
Ransom paid
~$15M
Reported; ~half of ~$30M demand
Operational outage
None
Operations continued, per 8-K
Initial access
Vendor
Social engineering, outsourced IT support
Data stolen
DL + SSN
Caesars Rewards loyalty database
Section CZR.1
A social-engineered outsourced IT vendor
In its 8-K filing, Caesars stated that it "recently identified suspicious activity in its information technology network resulting from a social engineering attack on an outsourced IT support vendor used by the Company." The intrusion did not exploit a Caesars software flaw or a stolen Caesars credential; it exploited a third party with access, defeated by the same LinkedIn-plus-help-desk voice-phishing playbook that Scattered Spider (tracked as UNC3944) used against MGM. Contemporaneous reporting placed the initial unauthorized access in mid-to-late August 2023, with Caesars determining the scope of the theft on 7 September 2023 and disclosing publicly on 14 September 2023.
The single most important operational fact is what did not happen. Caesars stated in the 8-K that "our customer-facing operations, including our physical properties and our online and mobile gaming applications, have not been impacted by this incident and continue without disruption." Where MGM took its own systems offline to contain the attack and absorbed a ten-day outage, Caesars kept trading. That difference in operational impact is the crux of why the two incidents cost such different things.
Section CZR.2
The cost composition
| Cost line item | Amount | Source |
|---|---|---|
| Ransom paid | ~$15M | Reported (Bloomberg); ~half of a ~$30M demand |
| Operational / revenue impact from outage | None disclosed | 8-K: operations "continue without disruption" |
| Response, remediation and investigation costs | Incurred, not quantified | 8-K; expected partly offset by cyber insurance |
| Credit monitoring & identity protection | Offered to all loyalty members | 8-K (idx.us notification programme) |
| Class-action litigation | Ongoing (no final settlement) | Consolidated federal data-breach litigation |
| Reference: MGM (same actor) outage impact | ~$100M EBITDAR | MGM refused; absorbed a ~10-day outage |
Caesars never confirmed a ransom figure. Its 8-K used the now-notorious euphemism: "We have taken steps to ensure that the stolen data is deleted by the unauthorized actor, although we cannot guarantee this result." That sentence is how a public company discloses a ransom payment without using the word. The ~$15 million figure (roughly half of a reported ~$30 million demand) comes from press reporting, not the filing, and should be read as reported rather than confirmed. Caesars stated it did not expect the incident to have a material effect on its financial condition or results of operations.
Section CZR.3
What was stolen, and how many were affected
Caesars disclosed that the unauthorized actor "acquired a copy of, among other data, our loyalty program database, which includes driver's license numbers and/or social security numbers for a significant number of members in the database." The company added that it had "no evidence to date that any member passwords/PINs, bank account information, or payment card information (PCI) were acquired," and offered credit monitoring and identity-theft protection to all members of the Caesars Rewards programme.
The 8-K did not state a total number of affected people. The Caesars Rewards programme has tens of millions of members, and reporting frequently cites a figure in the region of 65 million to describe the database as a whole; that is the size of the loyalty base, not a confirmed count of affected individuals. State breach notifications give a firmer, if partial, floor: Caesars reported 41,397 affected residents to the Maine Attorney General alone. The honest framing is that a large but unquantified share of the Caesars Rewards membership had driver's license or Social Security data exposed.
Section CZR.4
Pay or refuse: the MGM comparison
The Caesars and MGM incidents happened within days of each other, attributed to the same Scattered Spider ecosystem, against the same industry, using the same social-engineering technique. They then diverged on the one decision every ransomware victim faces. Caesars reportedly paid roughly $15 million and kept its casinos and apps running. MGM refused, took systems offline to contain the attack, and disclosed an approximately $100 million negative impact to quarterly EBITDAR from a roughly ten-day outage, plus under $10 million in response costs and a later $45 million class settlement covering its 2019 and 2023 breaches.
On the headline arithmetic, Caesars' paid path looks far cheaper. But the comparison is not that clean. Paying a ransom funds a criminal enterprise, buys only an unenforceable promise that the data was deleted (Caesars itself said it "cannot guarantee" the result), invites repeat targeting, and does not extinguish the class-action and regulatory exposure that follows a loyalty-database theft regardless of whether the ransom was paid. MGM's refusal cost more in visible operational dollars but avoided funding the attackers and drew regulatory credit for not paying. Neither outcome is obviously the cheaper one once litigation, insurance, reputational effects, and the moral hazard of payment are all weighed, which is exactly why the pairing is now standard board-level teaching material.
Section CZR.5
Lessons: the vendor is the perimeter
The Caesars breach came through an outsourced IT support vendor, not through Caesars' own front door. That makes it a third-party and identity-verification failure as much as MGM's was a help-desk one: a supplier with privileged access, and the human at that supplier who could be talked into a reset, were the effective perimeter. The defensive response the two 2023 casino breaches drove is the same, extended to vendors: call-back verification and manager approval for any privileged-access reset, knowledge-based checks that cannot be scraped from LinkedIn, removal of unilateral MFA-reset authority for high-privilege accounts, and holding outsourced support providers to the same identity-verification standard as internal staff.
The second lesson is about disclosure. Caesars' "steps to ensure that the stolen data is deleted" sentence became a widely-cited example of how ransom payments surface in SEC filings without the word ransom appearing. For anyone reading breach 8-Ks to estimate cost, that euphemism is the tell: a company reporting that it has arranged for stolen data to be deleted is almost always reporting that it paid. Reading the disclosure literally, and pairing it with the absence of any operational-outage line, is how the Caesars cost profile becomes legible.
Cross-references
Case / MGM Resorts 2023
→The refuse-side counterpart: ~$100M outage, no ransom paid.
Case / Snowflake 2024
→The 2024 Scattered Spider-ecosystem cluster: ~165 customers.
Industry / Retail and hospitality
→Revenue-dense operations where downtime dominates cost.
Reference / Ransomware economics
→Pay-vs-refuse, median demands, and recovery costs.
Cost / Class-action settlement
→The litigation exposure a ransom payment does not extinguish.
Index / All breach cases
→18 verified mega-breaches.
Schedule F / Reference Q&A
Frequently Asked Questions
Primary source:Caesars Entertainment 2023 breach data from the company's SEC Form 8-K (Item 8.01, filed 14 September 2023, event date 7 September 2023), including the verbatim disclosure language on the social-engineering attack, the loyalty-database theft of driver's license and Social Security numbers, and the 'steps to ensure that the stolen data is deleted' statement. The reported ~$15M ransom (roughly half of a ~$30M demand) is from press reporting (Bloomberg) and is not confirmed in the filing. Affected-resident count from the Maine Attorney General breach notification (41,397). Attribution to Scattered Spider / UNC3944 and the parallel MGM comparison from contemporaneous reporting and MGM's own SEC filings (verified 27 July 2026).