First reportedSeptember 14, 2023
ActivitySeptember 7, 2023
Last updatedFeb 2, 2026, 12:00 AM UTC
Record confidencemed

Key facts

Affected

  • Caesars Rewards loyalty program members
  • Caesars Entertainment, Inc.

Initial access

  • stolen_creds
  • unknown

Impact

  • data_theft
  • extortion
  • financial_loss

Attribution

unknown low confidence

Cited SEC filing describes the incident; specific actor attribution is not provided in the filing.

CVEs and ATT&CK

CVEs

ATT&CK techniques

  • T1041: The SEC filing describes data exfiltration from the loyalty program database; the method of exfiltration is not detailed.

Mitigations

Now

  • Enforce phishing-resistant MFA for workforce and privileged accountsReduces successful account takeovers from stolen passwords and common social engineering techniques.

Soon

  • Harden helpdesk and password reset workflowsPrevents attackers from using social engineering to reset MFA or regain access via the identity recovery channel.

Later

  • Apply conditional access and session risk controls (device posture, geo, impossible travel)Limits account abuse by requiring stronger signals for high-risk sign-ins and reducing lateral access after compromise.

Detection ideas

Alert on anomalous authentication patterns

Flag first-time device logins, new geo/ASN, impossible travel, and sign-ins immediately followed by privilege escalation or access to sensitive apps.

Data sources: IdP sign-in logs, SSO audit logs, VPN authentication logs

Detect risky account recovery and MFA changes

Alert when MFA factors are reset/added, recovery email/phone is changed, or helpdesk performs high-risk password resets outside normal hours.

Data sources: IdP audit logs, Helpdesk/ticketing logs

Sources