Caesars Entertainment pays ransom to hackers

Share post:

Caesars Entertainment, one of the world’s largest casino operators, has reportedly paid “tens of millions of dollars” to hackers who threatened to release company data, according to Bloomberg.

The attack was reportedly perpetrated by a group called Scattered Spider (aka UNC 3944), a group skilled at using social engineering to bypass corporate network security.

Scattered Spider’s members, some as young as 19, are believed to operate from the United States and the United Kingdom. Their campaign against Caesars began as early as August 27th, with the group gaining access to an external vendor before infiltrating the company’s inner sanctum.

Once inside the network, Scattered Spider reportedly exploited vulnerabilities and used tools like “Stonestop” to evade security software. Stonestop is a type of malware that can disable security software and steal data.

It is unclear how much data was stolen in the attack, but Caesars has not disclosed any evidence that customer data was compromised. The company is expected to disclose the attack “imminently” in a regulatory filing.

Scattered Spider is known for using social engineering to gain access to corporate networks. Social engineering is a type of attack that relies on human error and manipulation to trick victims into revealing confidential information or clicking on malicious links.

The sources for this piece include an article in Engadget.

SUBSCRIBE NOW

Related articles

North Korean hacker infiltrates US security vendor, loads malware

KnowBe4, a US-based security vendor, unknowingly hired a North Korean hacker who attempted to introduce malware into the...

CrowdStrike releases an update from initial Post Incident Review: Hashtag Trending Special Edition for Thursday July 25, 2024

Security vendor CrowdStrike released an update on from their initial Post Incident Review today. The first, and most surprising...

Security vendor CrowdStrike issues an update from their initial Post Incident Review

Security vendor CrowdStrike released an update from their initial Post Incident Review (PIR) today. The company's CEO has...

CrowdStrike CEO summoned by Homeland Security committee over software disaster

CrowdStrike CEO George Kurtz has been called to testify before the U.S. House Committee on Homeland Security following...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways