CAESARS · LOYALTY DATABASE · DATA BREACH
Attackers obtained a copy of Caesars' loyalty-program database containing government-identification information for a significant number of members.
Customer identification retained → centralized database → attacker obtains copy
In a 2023 SEC filing, Caesars disclosed that an attacker acquired a copy of its loyalty-program database. The company said the database included driver's-license numbers and/or Social Security numbers for a significant number of members.
Why it matters: Casinos have unusually strong fraud and security reasons for identifying customers. That does not eliminate the separate question created by retaining valuable identity information: who must secure it, and what happens when they fail?
Primary source: Caesars Entertainment — SEC Form 8-K, 2023
This page preserves the anecdote and its caveats separately from the shorter Why Privacy Matters explainer. The goal is to keep the argument readable without hiding the receipts.