Skip to content

Caesars Entertainment

Disclosed Sep 14, 20233 years agoConfirmed

Official notice

Social engineering of IT vendor leads to theft of Caesars Rewards loyalty database

Caesars disclosed that a social engineering attack on an outsourced IT support vendor let an attacker copy its loyalty program database, which included driver's license and Social Security numbers for a significant number of members. It offered credit monitoring to all loyalty members.

What is known

People affectedNot stated in the sources we have
DisclosedSep 14, 2023
DiscoveredAug 19, 2023
HappenedAug 23, 2023
AttackPhishing
Data exposedNames, Government IDs, Social Security numbers
SectorHospitality · US
StatusConfirmed

Sources

Source
California Attorney General breach notice: Caesars Entertainmentoag.ca.gov · Official notice
Washington Attorney General breach notice: Caesars Entertainmentatg.wa.gov · Official notice
Notice letter filed with the Delaware DOJ: Caesars Entertainmentattorneygeneral.delaware.gov · Official notice
Oregon DOJ breach notice: Caesars Entertainmentjustice.oregon.gov · Official notice
California AG data breach notice: Caesars Entertainment, Inc.oag.ca.gov · Regulator
Caesars Entertainment, Inc. Form 8-K, September 14, 2023sec.gov · SEC filing
Indiana Attorney General 2023 data breach report: Caesars Entertainmentin.gov · Official notice

Notices filed

WhereFiledPeople
ResearchtotalSep 14, 2023
Washington AGresidents of WAOct 6, 2023784,234
Delaware DOJresidents of DEOct 6, 2023154,611
Indiana AGresidents of INOct 6, 20231,662,718
California AGresidents of CAOct 11, 2023
Oregon DOJresidents of OROct 18, 2023271,637

Other breaches at Caesars Entertainment

BreachAffected
Disclosed May 19, 2026May 194 months agoHacking862
Disclosed Sep 1, 2017Sep 1, 20179 years ago162
Disclosed Nov 28, 2016Nov 28, 20169 years ago1,439
History of this record
  • 2026-09-25 · source: empty to https://www.in.gov/attorneygeneral/consumer-protection-division/id-theft-prevention/files/D-BYear-to-Date-Report-2023.pdf · backfill source
  • 2026-09-25 · sector: media to hospitality · seed source
  • 2026-09-25 · attack: hacking to phishing · seed source
  • 2026-09-25 · data_types: ["names"] to ["names","government-id","ssn"] · seed source
  • 2026-09-25 · disclosed: 2023-10-06 to 2023-09-14 · seed source
  • 2026-09-25 · summary: empty to Caesars disclosed that a social engineering attack on an outsourced IT support vendor let an attacker copy its loyalty program database, which included driver's license and Social Security numbers for a significant number of members. It off · seed source
  • 2026-09-25 · title: empty to Social engineering of IT vendor leads to theft of Caesars Rewards loyalty database · seed source
  • 2026-09-25 · data_types: [] to ["names"] · backfill source
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · disclosed: 2023-10-11 to 2023-10-06 · backfill source
  • 2026-09-25 · discovered: empty to 2023-08-19 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about Caesars Entertainment

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.