
What happened
Caesars Entertainment and MGM Resorts each disclosed a cybersecurity incident to the Securities and Exchange Commission in September 2023. Caesars' 8-K filing said it identified suspicious activity on 7 September 2023 that it attributed to a social-engineering attack on an outsourced IT support vendor. The unauthorised actor obtained a copy of Caesars' loyalty-program database, including driver's licence numbers and Social Security numbers for a significant number of members. Caesars said it found no evidence that passwords, PINs, bank details or payment-card data were taken, and that it had taken steps meant to get the stolen data deleted, while acknowledging it could not guarantee that outcome.
MGM Resorts' initial disclosure, dated 12 September 2023, described a cybersecurity issue affecting certain systems and said MGM had shut down some systems to protect data while it investigated with outside experts. A follow-up 8-K filed on 5 October 2023 estimated roughly 100 million dollars of negative impact to Adjusted Property EBITDAR in September, mostly at its Las Vegas Strip properties, plus under 10 million dollars in one-time consulting and legal costs. MGM said no payment-card numbers, passwords or bank account numbers were obtained, but that names, contact details, dates of birth and driver's licence numbers were, with Social Security and passport numbers taken for a limited subset of customers.
Confidence and limits
Caesars' own filing names the initial-access method: social engineering directed at an outsourced help desk. MGM's filings describe scope and cost but do not themselves specify an initial-access vector. A joint advisory published two months later describes a broader pattern of impersonating IT help-desk staff to obtain password resets and multi-factor bypass, consistent with what became widely understood about this period of activity, but the advisory is a general pattern description rather than a finding about either specific company.
Why it mattered
The same starting point, an outsourced help desk granting access it should not have, produced different second-order effects. Caesars' filing describes steps taken to have stolen data deleted by the actor, implying continued contact with the attacker, while MGM's filings describe an extended shutdown across casino floors, reservations and loyalty systems and a nine-figure impact on a single month's results. Both companies pointed, in substance, to the same weakness: verifying a caller's identity before a password reset or a multi-factor change.
Defensive takeaway
Check whether your own help desk can grant a password reset or multi-factor enrolment change based on a phone call alone, and consider requiring a second, independent verification step, such as a callback to a number already on file, before any high-privilege account is touched.
- Can your help desk reset a privileged account's credentials or MFA enrolment without verifying the caller against something they could not plausibly know?
- Do your outsourced IT support contracts specify identity-verification standards, and are they audited?
- Would your organisation notice a wave of help-desk password-reset requests as an anomaly rather than routine volume?
Neither filing proves which technique compromised MGM's systems, and readers should treat the CISA advisory as background on a broader pattern, not a confirmed account of either incident.
Check whether your help desk can reset a privileged account's credentials or multi-factor enrolment based on a phone call alone, and require an independent verification step, such as a callback to a number already on file, before any such change.
Caesars' own filing names social engineering against an outsourced help desk as the initial vector. MGM's filings describe scope and cost without specifying a vector, so any help-desk attribution for MGM here rests on a general pattern advisory rather than MGM's own account.
Sources & reading trail
Caesars' own filing attributes the incident to social engineering against an outsourced IT support vendor and describes the loyalty-database data taken.
company-primary · Source published: 14 September 2023 · Retrieved: 16 September 2026
MGM's initial disclosure describes shutting down systems in response to a cybersecurity issue, without specifying an initial-access method.
company-primary · Source published: 13 September 2023 · Retrieved: 16 September 2026
Quantifies the incident's financial impact and lists the categories of customer data taken.
company-primary · Source published: 5 October 2023 · Retrieved: 16 September 2026
Describes the general pattern of IT help-desk impersonation and multi-factor bypass associated with this period's activity, without naming a specific victim.
government-primary · Source published: 16 November 2023 · Retrieved: 16 September 2026
Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.