Social EngineeringPhishingSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICMediumContained
CAESARS ENTERTAINMENT, INC.
bd_3808f9e72f2d34c3 · schema v1 · pii pii-v1
Full breach record for CAESARS ENTERTAINMENT, INC. →Caesars Entertainment, Inc. notified the New Hampshire Attorney General on October 6, 2023, of a data security incident affecting approximately 59,221 state residents. The breach resulted from a social engineering attack targeting an outsourced IT support vendor (supply chain compromise) on August 19, 2023. The unauthorized actor accessed the loyalty program database, compromising personal information of members. Caesars offered two years of credit monitoring and identity protection services to affected individuals.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_05c8c6491430b9e6Maine State AGfiled 2023-10-06Verified
- bd_272f94a6f3de2ba4Washington State AGfiled 2023-10-06Verified
- bd_69a1d6b1c88c08cdDelaware State AGfiled 2023-10-06Verified
- bd_99384d40133c3f20Montana State AGfiled 2023-10-06Verified
Show 4 more filings ↓Show fewer ↑up to 22d gap
- bd_4875e85583699d0eHawaii State AGfiled 2023-10-11(5d gap)Verified
- bd_f8b5acb3346f154cCalifornia State AGfiled 2023-10-11(5d gap)Verified
- bd_e9281b4209172a1fOregon State AGfiled 2023-10-18(12d gap)Verified
- bd_e06f962db935cb32SEC 8-Kfiled 2023-09-14(22d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/caesars-entertainment-20231006.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 6, 2023
- Raw hash
- 5a782429745fcf70783fc37df51585c0cf9be3c8e4e681e03c0c9d30568fb9e2
Reporting entity
- Name
- CAESARS ENTERTAINMENT, INC.norm: caesars entertainment
Victim entity
- Name
- CAESARS ENTERTAINMENT, INC.norm: caesars entertainment
Incident
- Discovered
- Aug 19, 2023
- Materiality determined
- Sep 14, 2023
- Notification sent
- Oct 6, 2023
- Affected individuals
- 59,221
- Data types
- IDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- notified state gaming regulators
- Initial access
- supply_chain
Compliance
- Time to disclose
- 7 weeks(48 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.