Caesars Entertainment
Disclosed Sep 14, 20233 years agoConfirmed
Social engineering of IT vendor leads to theft of Caesars Rewards loyalty database
Caesars disclosed that a social engineering attack on an outsourced IT support vendor let an attacker copy its loyalty program database, which included driver's license and Social Security numbers for a significant number of members. It offered credit monitoring to all loyalty members.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Sep 14, 2023 |
| Discovered | Aug 19, 2023 |
| Happened | Aug 23, 2023 |
| Attack | Phishing |
| Data exposed | Names, Government IDs, Social Security numbers |
| Sector | Hospitality · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: Caesars Entertainmentoag.ca.gov · Official notice | Official notice |
| Washington Attorney General breach notice: Caesars Entertainmentatg.wa.gov · Official notice | Official notice |
| Notice letter filed with the Delaware DOJ: Caesars Entertainmentattorneygeneral.delaware.gov · Official notice | Official notice |
| Oregon DOJ breach notice: Caesars Entertainmentjustice.oregon.gov · Official notice | Official notice |
| California AG data breach notice: Caesars Entertainment, Inc.oag.ca.gov · Regulator | Regulator |
| Caesars Entertainment, Inc. Form 8-K, September 14, 2023sec.gov · SEC filing | SEC filing |
| Indiana Attorney General 2023 data breach report: Caesars Entertainmentin.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Sep 14, 2023 | |
| Washington AGresidents of WA | Oct 6, 2023 | 784,234 |
| Delaware DOJresidents of DE | Oct 6, 2023 | 154,611 |
| Indiana AGresidents of IN | Oct 6, 2023 | 1,662,718 |
| California AGresidents of CA | Oct 11, 2023 | |
| Oregon DOJresidents of OR | Oct 18, 2023 | 271,637 |
Other breaches at Caesars Entertainment
| Breach | Affected | ||||
|---|---|---|---|---|---|
| Disclosed May 19, 2026May 194 months agoHacking | May 194 months ago | Hacking | Media | Confirmed | 862 |
| Disclosed Sep 1, 2017Sep 1, 20179 years ago | Sep 1, 20179 years ago | Not stated | Media | Confirmed | 162 |
| Disclosed Nov 28, 2016Nov 28, 20169 years ago | Nov 28, 20169 years ago | Not stated | Media | Confirmed | 1,439 |
History of this record
- 2026-09-25 · source: empty to https://www.in.gov/attorneygeneral/consumer-protection-division/id-theft-prevention/files/D-BYear-to-Date-Report-2023.pdf · backfill source
- 2026-09-25 · sector: media to hospitality · seed source
- 2026-09-25 · attack: hacking to phishing · seed source
- 2026-09-25 · data_types: ["names"] to ["names","government-id","ssn"] · seed source
- 2026-09-25 · disclosed: 2023-10-06 to 2023-09-14 · seed source
- 2026-09-25 · summary: empty to Caesars disclosed that a social engineering attack on an outsourced IT support vendor let an attacker copy its loyalty program database, which included driver's license and Social Security numbers for a significant number of members. It off · seed source
- 2026-09-25 · title: empty to Social engineering of IT vendor leads to theft of Caesars Rewards loyalty database · seed source
- 2026-09-25 · data_types: [] to ["names"] · backfill source
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · disclosed: 2023-10-11 to 2023-10-06 · backfill source
- 2026-09-25 · discovered: empty to 2023-08-19 · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.