RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The incident desk · 100 retrospective records ↗

The incident desk / Incident

Incident / From the archive · September 2023 event · prepared 16 September 2026

Two casinos took different paths after help-desk social engineering

Caesars and MGM both disclosed 2023 breaches tied to IT help-desk deception, with different filings and outcomes.

Visual for this record: Two casinos took different paths after help-desk social engineering
Visual published by casino.org, shown for identification of the record. Credit: casino.org · source page ↗ Rights: owner-review-pending.

What happened

Caesars Entertainment and MGM Resorts each disclosed a cybersecurity incident to the Securities and Exchange Commission in September 2023. Caesars' 8-K filing said it identified suspicious activity on 7 September 2023 that it attributed to a social-engineering attack on an outsourced IT support vendor. The unauthorised actor obtained a copy of Caesars' loyalty-program database, including driver's licence numbers and Social Security numbers for a significant number of members. Caesars said it found no evidence that passwords, PINs, bank details or payment-card data were taken, and that it had taken steps meant to get the stolen data deleted, while acknowledging it could not guarantee that outcome.

MGM Resorts' initial disclosure, dated 12 September 2023, described a cybersecurity issue affecting certain systems and said MGM had shut down some systems to protect data while it investigated with outside experts. A follow-up 8-K filed on 5 October 2023 estimated roughly 100 million dollars of negative impact to Adjusted Property EBITDAR in September, mostly at its Las Vegas Strip properties, plus under 10 million dollars in one-time consulting and legal costs. MGM said no payment-card numbers, passwords or bank account numbers were obtained, but that names, contact details, dates of birth and driver's licence numbers were, with Social Security and passport numbers taken for a limited subset of customers.

Confidence and limits

Caesars' own filing names the initial-access method: social engineering directed at an outsourced help desk. MGM's filings describe scope and cost but do not themselves specify an initial-access vector. A joint advisory published two months later describes a broader pattern of impersonating IT help-desk staff to obtain password resets and multi-factor bypass, consistent with what became widely understood about this period of activity, but the advisory is a general pattern description rather than a finding about either specific company.

Why it mattered

The same starting point, an outsourced help desk granting access it should not have, produced different second-order effects. Caesars' filing describes steps taken to have stolen data deleted by the actor, implying continued contact with the attacker, while MGM's filings describe an extended shutdown across casino floors, reservations and loyalty systems and a nine-figure impact on a single month's results. Both companies pointed, in substance, to the same weakness: verifying a caller's identity before a password reset or a multi-factor change.

Defensive takeaway

Check whether your own help desk can grant a password reset or multi-factor enrolment change based on a phone call alone, and consider requiring a second, independent verification step, such as a callback to a number already on file, before any high-privilege account is touched.

  • Can your help desk reset a privileged account's credentials or MFA enrolment without verifying the caller against something they could not plausibly know?
  • Do your outsourced IT support contracts specify identity-verification standards, and are they audited?
  • Would your organisation notice a wave of help-desk password-reset requests as an anomaly rather than routine volume?

Neither filing proves which technique compromised MGM's systems, and readers should treat the CISA advisory as background on a broader pattern, not a confirmed account of either incident.

Defensive takeaway

Check whether your help desk can reset a privileged account's credentials or multi-factor enrolment based on a phone call alone, and require an independent verification step, such as a callback to a number already on file, before any such change.

Caesars' own filing names social engineering against an outsourced help desk as the initial vector. MGM's filings describe scope and cost without specifying a vector, so any help-desk attribution for MGM here rests on a general pattern advisory rather than MGM's own account.

Sources & reading trail

Caesars Entertainment, Inc. Form 8-K (Item 1.05) ↗

Caesars' own filing attributes the incident to social engineering against an outsourced IT support vendor and describes the loyalty-database data taken.

company-primary · Source published: 14 September 2023 · Retrieved: 16 September 2026

MGM Resorts International Form 8-K, Exhibit 99.1 (initial disclosure) ↗

MGM's initial disclosure describes shutting down systems in response to a cybersecurity issue, without specifying an initial-access method.

company-primary · Source published: 13 September 2023 · Retrieved: 16 September 2026

MGM Resorts International Form 8-K (financial impact update) ↗

Quantifies the incident's financial impact and lists the categories of customer data taken.

company-primary · Source published: 5 October 2023 · Retrieved: 16 September 2026

Scattered Spider joint cybersecurity advisory (AA23-320A) ↗

Describes the general pattern of IT help-desk impersonation and multi-factor bypass associated with this period's activity, without naming a specific victim.

government-primary · Source published: 16 November 2023 · Retrieved: 16 September 2026

Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.