Caesars Entertainment is facing many lawsuits from hotel customers who claim that the company was negligent for allowing the theft of their sensitive personal data in a social engineering attack.

Caesars disclosed earlier this month that its customer rewards database was stolen following a hacker attack against an IT support vendor. Security researchers report that the incident was part of a larger operation by a group called Scattered Spider, which used voice phishing techniques against various organizations.
At least four lawsuits have been filed in the Federal Court of Nevada, with the plaintiffs seeking class-action status. The plaintiffs accuse the company of negligence, as it failed to protect the personal data of the hotel’s guests.
Caesars Entertainment, in a Sept. 14 filing with the Securities and Exchange Commission, confirmed that hackers obtained a copy of its frequent customer database, which contains Social Security Numbers and driver's licenses for a large number of customers.
The company Caesars Entertainment did not initially file a report regarding the attack, until the MGM attack was identified due to operational problems at these facilities. MGM disclosed its cyberattack via a press release on September 12 and with a filing with the SEC.
Caesars Entertainment announced that it continues to investigate what other information is part of the data breach, however it has no evidence that members' passwords, PIN codes, banking information, or credit card numbers were part of the breach, according to the SEC report.
Caesars Entertainment is one of the largest hotel and casino companies in the world and a major player in the Las Vegas market. The Reno, Nevada -based company operates more than 47,000 hotel rooms in 16 states.
Information source: cybersecuritydive.com
