FEDERALItem 8.01 · voluntarySocial EngineeringPhishingMulti-Stage ChainData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_GOVERNMENTIDENTITY_BASICMediumActive
CAESARS ENTERTAINMENT, INC.
bd_e06f962db935cb32 · schema v1 · pii pii-v1
Full breach record for CAESARS ENTERTAINMENT, INC. →Caesars Entertainment, Inc. disclosed a cybersecurity incident on September 7, 2023, involving a social engineering attack targeting an outsourced IT support vendor. The attacker accessed the company's loyalty program database, obtaining driver's license numbers and Social Security numbers for a significant number of members. Customer-facing operations were not impacted. Caesars engaged cybersecurity firms, notified law enforcement and gaming regulators, and is offering credit monitoring services to affected loyalty program members.
SEC clockMateriality determined Sep 7, 2023 → Filed Sep 14, 20237d ✗ SEC 4-day late7 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_05c8c6491430b9e6Maine State AGfiled 2023-10-06(22d gap)Verified
- bd_272f94a6f3de2ba4Washington State AGfiled 2023-10-06(22d gap)Verified
- bd_3808f9e72f2d34c3New Hampshire State AGfiled 2023-10-06(22d gap)Verified
- bd_69a1d6b1c88c08cdDelaware State AGfiled 2023-10-06(22d gap)Verified
Show 4 more filings ↓Show fewer ↑up to 34d gap
- bd_99384d40133c3f20Montana State AGfiled 2023-10-06(22d gap)Verified
- bd_4875e85583699d0eHawaii State AGfiled 2023-10-11(27d gap)Verified
- bd_f8b5acb3346f154cCalifornia State AGfiled 2023-10-11(27d gap)Verified
- bd_e9281b4209172a1fOregon State AGfiled 2023-10-18(34d gap)Verified
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/1590895/000119312523235015/d537840d8k.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Sep 14, 2023
- Raw hash
- e421f2498befc7e69248d16fb090f756c593d99ff65af084aa8e4e83bc8362e9
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- CAESARS ENTERTAINMENT, INC.norm: caesars entertainment
- SEC CIK
- 0001590895
Victim entity
- Name
- CAESARS ENTERTAINMENT, INC.norm: caesars entertainment
- SEC CIK
- 0001590895
Incident
- Discovered
- Sep 7, 2023
- Materiality determined
- Sep 7, 2023
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- notified state gaming regulators
- Initial access
- phishing_link
Compliance
- Time to disclose
- 7 days(7 days from discovery to filing)
- Compliance flags
- SEC 4-day late · 7d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Sep 7, 2023→ Filed: Sep 14, 20237d cal. 4 business days SEC 4-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.