ThreatPaper
Weak Evidence

Caesars Entertainment customers' IDs were exposed in the IDScan breach

Assessment

Caesars appears on IDScan.net's client list, which is the basis for coverage naming it. Caesars told Krebs on 2 September that it "has not been a client of IDScan.net and has not used VeriScan since February 2025," had no active accounts at the time of the incident, "did not authorize IDScan.net to retain data from its accounts," and was told by IDScan.net the incident should have no impact on it. Whether pre-2025 Caesars scans remained in the cloud under the "do not delete" default is unknown. No Caesars-sourced record has been publicly identified.

Where this claim appeared

Startup Fortune · 2026-09-05

https://startupfortune.com/idscan-breach-exposes-153-million-drivers-licenses-tied-to-hertz-and-target/

What “Weak Evidence” means

Evidence exists but is thin, circumstantial, or explicitly qualified as weak by the source that published it. Shared hosting infrastructure between threat clusters is the recurring example.

3 of 5 · rating scale

Assessed in

IDScan.net Breach: 153 Million Driver's Licence Scans and the Default Setting That Kept Them

Think this assessment is wrong? Report an error.