CAESARS · LOYALTY DATABASE · DATA BREACH

Attackers obtained a copy of Caesars' loyalty-program database containing government-identification information for a significant number of members.

Customer identification retained → centralized database → attacker obtains copy

In a 2023 SEC filing, Caesars disclosed that an attacker acquired a copy of its loyalty-program database. The company said the database included driver's-license numbers and/or Social Security numbers for a significant number of members.

Why it matters: Casinos have unusually strong fraud and security reasons for identifying customers. That does not eliminate the separate question created by retaining valuable identity information: who must secure it, and what happens when they fail?

Primary source: Caesars Entertainment — SEC Form 8-K, 2023

WHY THIS LIBRARY EXISTS

This page preserves the anecdote and its caveats separately from the shorter Why Privacy Matters explainer. The goal is to keep the argument readable without hiding the receipts.