* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Tuesday, July 1, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    Nantucket Dance Festival opens July 8 – The Inquirer and Mirror

    Nantucket Dance Festival Launches with Thrilling Performances Beginning July 8

    A Secret Society, Ritualistic Killings, and a Century-Old Curse Netflix and YRF Entertainment’s ‘Mandala Murders’ Premieres July 25 – About Netflix

    A Secret Society, Ritualistic Killings, and a Century-Old Curse: Dive into the Chilling World of ‘Mandala Murders’ Premiering July 25

    Susquehanna Raises Penn Entertainment Inc. (PENN) Price Target. – Yahoo Finance

    Susquehanna Raises Price Target for Penn Entertainment Inc. (PENN)

    George Lopez is coming to Spokane – KXLY.com

    George Lopez is coming to Spokane – KXLY.com

    Netflix unveils Dallas immersive venue for fans of hit shows like ‘Squid Game,’ ‘Stranger Things’ – Houston Chronicle

    Step Inside Netflix’s New Dallas Immersive Experience Featuring Hits Like ‘Squid Game’ and ‘Stranger Things

    ‘Puttin’ on the Ritz’: Civic Players bring ‘Young Frankenstein’ to life – Yahoo

    Civic Players Deliver a Hilarious and Unforgettable Performance of ‘Young Frankenstein

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Owls inspire new revolutionary noise reduction technology – KTEN

    Owls inspire new revolutionary noise reduction technology – KTEN

    New center coming to Mizzou will focus on energy research and technology – Columbia Missourian

    Mizzou Launches Innovative New Center Dedicated to Energy Research and Technology

    Mirrors in space and underwater curtains: can technology buy us enough time to save the Arctic ice caps? – The Guardian

    Can Technology Like Space Mirrors and Underwater Curtains Buy Us Time to Save the Arctic Ice Caps?

    Naples restaurant owner prepares for hurricane season with new flood technology – Fox4Now.com

    Naples restaurant owner prepares for hurricane season with new flood technology – Fox4Now.com

    Emerging Memory and Storage Technology Market Analysis Report 2025-2034 | AI and HPC Boom Fuels Surging Demand for Fast, Low-Power Memory Devices – Yahoo Finance

    How AI and HPC Are Driving Explosive Growth in Fast, Low-Power Memory Technologies Through 2034

    Ostin Technology (OST): Volatility’s Warning or Contrarian Opportunity? – AInvest

    Ostin Technology (OST): Navigating Market Volatility – Red Flag or Hidden Opportunity?

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    Nantucket Dance Festival opens July 8 – The Inquirer and Mirror

    Nantucket Dance Festival Launches with Thrilling Performances Beginning July 8

    A Secret Society, Ritualistic Killings, and a Century-Old Curse Netflix and YRF Entertainment’s ‘Mandala Murders’ Premieres July 25 – About Netflix

    A Secret Society, Ritualistic Killings, and a Century-Old Curse: Dive into the Chilling World of ‘Mandala Murders’ Premiering July 25

    Susquehanna Raises Penn Entertainment Inc. (PENN) Price Target. – Yahoo Finance

    Susquehanna Raises Price Target for Penn Entertainment Inc. (PENN)

    George Lopez is coming to Spokane – KXLY.com

    George Lopez is coming to Spokane – KXLY.com

    Netflix unveils Dallas immersive venue for fans of hit shows like ‘Squid Game,’ ‘Stranger Things’ – Houston Chronicle

    Step Inside Netflix’s New Dallas Immersive Experience Featuring Hits Like ‘Squid Game’ and ‘Stranger Things

    ‘Puttin’ on the Ritz’: Civic Players bring ‘Young Frankenstein’ to life – Yahoo

    Civic Players Deliver a Hilarious and Unforgettable Performance of ‘Young Frankenstein

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Owls inspire new revolutionary noise reduction technology – KTEN

    Owls inspire new revolutionary noise reduction technology – KTEN

    New center coming to Mizzou will focus on energy research and technology – Columbia Missourian

    Mizzou Launches Innovative New Center Dedicated to Energy Research and Technology

    Mirrors in space and underwater curtains: can technology buy us enough time to save the Arctic ice caps? – The Guardian

    Can Technology Like Space Mirrors and Underwater Curtains Buy Us Time to Save the Arctic Ice Caps?

    Naples restaurant owner prepares for hurricane season with new flood technology – Fox4Now.com

    Naples restaurant owner prepares for hurricane season with new flood technology – Fox4Now.com

    Emerging Memory and Storage Technology Market Analysis Report 2025-2034 | AI and HPC Boom Fuels Surging Demand for Fast, Low-Power Memory Devices – Yahoo Finance

    How AI and HPC Are Driving Explosive Growth in Fast, Low-Power Memory Technologies Through 2034

    Ostin Technology (OST): Volatility’s Warning or Contrarian Opportunity? – AInvest

    Ostin Technology (OST): Navigating Market Volatility – Red Flag or Hidden Opportunity?

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

Las Vegas mainstay Caesars Palace likely paid off ransomware crew

September 17, 2023
in Technology
Las Vegas mainstay Caesars Palace likely paid off ransomware crew
Share on FacebookShare on Twitter

Caesars Entertainment, owner of the lavish Roman Empire-themed Caesars Palace casino in Las Vegas, has revealed it also suffered a ransomware attack, and appears to have paid off its hackers

Alex Scroxton

By

Alex Scroxton,
Security Editor

Published: 15 Sep 2023 12:35

Caesars Entertainment, operator of the venerable Las Vegas casino Caesars Palace, has revealed that it paid a significant sum of money to its attackers following a recent ransomware attack, which was possibly the work of the same threat actor that breached competitor MGM Resorts using the ALPHV/BlackCat ransomware.

In a filing made to the US Securities and Exchange Commission (SEC), Caesars Entertainment said it initially became aware of the incident after identifying suspicious activity on its network. The subsequent investigation, which concluded on 7 September, found that the organisation was breached via a social engineering attack on an outsourced IT support supplier.

Its customer-facing operations, hotels, and online and mobile gaming services were not affected, however, Caesars Entertainment found that its attacker was able to purloin a copy of its loyalty programme database, including driver’s licence and social security numbers of thousands of guests and gamblers, although there is currently no evidence that any financial data was stolen. It is in the process of notifying victims.

Caesars Entertainment went on to make a statement that strongly implies it negotiated and paid at least part of the ransom demanded by its attacker.

It said: “We have taken steps to ensure that the stolen data is deleted by the unauthorised actor, although we cannot guarantee this result. We are monitoring the web and have not seen any evidence that the data has been further shared, published, or otherwise misused.”

According to reports, the ransom paid may have been as much as $15m, negotiated down from $30m, although this is unconfirmed.

Nevertheless, the apparent admission of ransom payment, which runs contrary to all accepted best practice, may store trouble for the entertainment giant, given strict regulatory policies implemented by the US government’s Office of Foreign Assets Control (OFAC) three years ago, which made making or facilitating ransomware payments a potential sanctions risk under US law.

High-rolling threat actor

Caesars Entertainment did not disclose any details of the group that extorted it, but given the near-simultaneous incident affecting its neighbours at MGM Resorts – and the fact that both incidents appear to have begun via social engineering – the attack is being widely linked to a threat actor tracked by Google Cloud’s Mandiant as UNC3944, using the ALPHV/BlackCat locker.

Also known as 0ktapus, Scattered Spider and Scatter Swine, UNC3944 made a name for itself in 2022 via an audacious series of social engineering attacks exploiting the trust that customers of identity and access management (IAM) specialist Okta placed in the brand.

Note that there is no firm evidence that implicates Okta in the incidents at either MGM Resorts or Caesars Entertainment, although a new wave of social engineering attacks against its customers was reported earlier this month and an as-yet unsubstantiated claim has been made in this regard by those claiming to be behind the MGM attack. Computer Weekly has contacted Okta for comment.

The high-rolling UNC3944 gang got its start conducting phone-based social engineering and SMS phishing (smishing) attacks, but according to Mandiant’s latest intelligence, it pivoted to deploying ransomware in summer 2023, and in the process expanded its targeting beyond the tech industry to include firms in the entertainment, hospitality, media and retail sectors.

It has also become more tightly focused on stealing sensitive data for extortion purposes, and in a change to the scheduled programme, may not actually be based in Russia – it demonstrates a competent understanding of Western business practices and many members are likely native English speakers.

Mandiant said the group works to “an extremely high operational tempo”, accessing critical systems and stealing large volumes of data very fast. This factor may be designed to “overwhelm” security response teams.

After gaining initial access via social engineering, UNC3944 enlists commercial residential proxy services to access their victims from the same geographical area, an attempt to fool monitoring tools looking out for suspicious traffic from elsewhere, and legitimate software including remote access tools.

Its operatives also dedicate significant resource to rooting out information that may help them escalate their privileges and maintain persistence, often targeting password management tools and privileged access management (PAM) systems to do so.

It has been frequently observed creating unmanaged virtual machines (VMs) in victim environments to launch attacks – in some cases these VMs are created inside victims’ cloud environments and are internet-accessible.

“We anticipate that intrusions related to UNC3944 will continue to involve diverse tools, techniques and monetisation tactics as the actors identify new partners and switch between different communities”

Mandiant researchers

When it’s time to deploy a ransomware locker, UNC3944 likes to target business-critical VMs and other systems to cause as much pain as possible, and ramps up the pressure by leaving threatening notes on compromised systems, bombarding executives with text messages and emails, and infiltrating internal comms channels used for incident response.

“UNC3944 is an evolving threat that has continued to broaden its skills and tactics in order to successfully diversify its monetisation strategies,” said Mandiant’s researchers.

“We expect that these threat actors will continue to improve their tradecraft over time and may leverage underground communities for support to increase the efficacy of their operations.

“UNC3944’s initial successes likely emboldened it to expand its TTPs to more disruptive and profitable attacks, including ransomware and extortion. It is plausible that these threat actors may use other ransomware brands and/or incorporate additional monetisation strategies to maximise their profits in the future.

“We anticipate that intrusions related to UNC3944 will continue to involve diverse tools, techniques and monetisation tactics as the actors identify new partners and switch between different communities,” they added.

Read more on Data breach incident management and recovery


Caesars Entertainment breached in social engineering attack

AlexanderCulafi

By: Alexander Culafi


BlackCat on the hook for cyber attack that crippled Vegas casinos

AlexScroxton

By: Alex Scroxton


US casino giant MGM Resorts battles 36-hour outage after cyber attack

AlexScroxton

By: Alex Scroxton


Okta: 4 customers compromised in social engineering attacks

ArielleWaldman

By: Arielle Waldman

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : Computer Weekly – https://www.computerweekly.com/news/366552124/Las-Vegas-mainstay-Ceasars-Palace-likely-paid-off-ransomware-crew

Tags: mainstaytechnologyVegas
Previous Post

Number of UK contactless payments rose by 30% last year

Next Post

Chatham Rock Phosphate posts Korella North NI 43-101 resource estimate, Australia

He’s searching for a human-made problem in areas largely untouched by humans. Answers are just emerging – CNN

He’s searching for a human-made problem in areas largely untouched by humans. Answers are just emerging – CNN

July 1, 2025
Asteroid 2024 YR4 might smash into the moon – Popular Science

Urgent Alert: Asteroid 2024 YR4 Headed Straight for the Moon!

July 1, 2025
These 9 towns were named the ‘quirkiest’ in New Jersey, according to World Atlas – Bergen Record

These 9 towns were named the ‘quirkiest’ in New Jersey, according to World Atlas – Bergen Record

July 1, 2025
Trump’s Tax Bill Won’t Help or Hurt the Economy. The Deficit Is Already Huge. – Barron’s

Trump’s Tax Bill Won’t Help or Hurt the Economy. The Deficit Is Already Huge. – Barron’s

July 1, 2025
Nantucket Dance Festival opens July 8 – The Inquirer and Mirror

Nantucket Dance Festival Launches with Thrilling Performances Beginning July 8

July 1, 2025
Who would be affected by health care cuts in Senate version of Trump’s budget bill – PBS

Who Will Be Hit Hardest by Health Care Cuts in the Senate’s Trump Budget Plan?

July 1, 2025
Senate passes Trump’s reconciliation bill with Vance casting tie-breaking vote – PBS

Senate Passes Trump’s Reconciliation Bill After Vance Casts Decisive Tie-Breaking Vote

July 1, 2025
Groundbreaking technology to help police tackle violence against women – The Independent

Revolutionary Technology Transforms the Fight Against Violence Toward Women

July 1, 2025
Apple Inc. (AAPL) Adds Tennis To Its List of Supported Sports Ahead of Wimbledon – Yahoo Finance

Apple Inc. (AAPL) Adds Tennis To Its List of Supported Sports Ahead of Wimbledon – Yahoo Finance

July 1, 2025
Nature’s headlamps: A unique light-focusing structure in Parasesarma de Man, 1895 mangrove crabs – ESA Journals

Nature’s headlamps: A unique light-focusing structure in Parasesarma de Man, 1895 mangrove crabs – ESA Journals

July 1, 2025

Categories

Archives

July 2025
MTWTFSS
 123456
78910111213
14151617181920
21222324252627
28293031 
« Jun    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (701)
  • Economy (726)
  • Entertainment (21,615)
  • General (15,657)
  • Health (9,766)
  • Lifestyle (731)
  • News (22,149)
  • People (727)
  • Politics (733)
  • Science (15,944)
  • Sports (21,223)
  • Technology (15,710)
  • World (707)

Recent News

He’s searching for a human-made problem in areas largely untouched by humans. Answers are just emerging – CNN

He’s searching for a human-made problem in areas largely untouched by humans. Answers are just emerging – CNN

July 1, 2025
Asteroid 2024 YR4 might smash into the moon – Popular Science

Urgent Alert: Asteroid 2024 YR4 Headed Straight for the Moon!

July 1, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version