Gill v. Caesars Entertainment, Inc.

District Court, D. Nevada·Decided August 15, 2025·No. 2:23-cv-01447·Unknown

Opinion

2 UNITED STATES DISTRICT COURT

3 DISTRICT OF NEVADA

4 Case No. 2:23-cv-01447-ART-BNW 5 In re: DATA BREACH SECURITY ORDER DENYING DEFENDANT’S 6 LITIGATION AGAINST CAESARS MOTION TO DISMISS ENTERTAINMENT, INC. 7 (ECF No. 91) 8 9 This is a consolidated class action against Defendant Caesars 10 Entertainment, Inc. (“Caesars”) relating to a data breach. In August 2023, 11 Caesars’ Rewards member database was hacked, and Plaintiffs’ personal 12 identifying information (“PII”) was accessed by hackers. Plaintiffs were members 13 of Caesars’ rewards program and/or customers of Caesars’ gaming and 14 entertainment services at the time. Plaintiffs bring a putative class action seeking 15 redress for the harms they allegedly suffered from the data breach. (See ECF No. 16 81 (“Consolidated Class Action Complaint”).) 17 Before the Court is Defendant’s motion to dismiss for lack of standing and 18 failure to state a claim. (ECF No. 91.) For the following reasons, the Court finds 19 that Plaintiffs have standing, and that Plaintiffs have plausibly pled each of their 20 claims. Accordingly, Defendant’s motion to dismiss is denied. 21 I. BACKGROUND 22 A. Summary of Allegations 23 On or around August 18, 2023, members of the cybercriminal group 24 Scattered Spider gained access to Caesars’ loyalty program database through a 25 social engineering attack on Caesars’ IT support company.1 (ECF No. 81 at ¶¶ 2, 26

28 1 Plaintiffs’ lawsuit against that company, Coforge, Ltd. (“Coforge”), has since 1 224, 225.) The database contained sensitive PII, including names, drivers’ license 2 numbers, and social security numbers of a “significant number” of Caesars’ 3 loyalty program’s 65 million members. (ECF No. 81 at ¶ 1.) Caesars identified the 4 suspicious activity on that day, yet Scattered Spider downloaded the PII five days 5 later. (Id. at ¶ 225.) 6 On September 7, 2023, Caesars’ interval investigation confirmed that 7 Scattered Spider had acquired, among other data, a copy of its loyalty program 8 database including names, driver’s license numbers, and social security numbers 9 for “a significant number of Caesars Rewards’ tens of millions of members.” (Id. 10 at ¶ 227.) On or around September 14, 2023, Caesars filed a Form 8-K with the 11 SEC to alert investors and shareholders that the data breach had occurred. (Id. 12 at ¶ 228.) Caesars also put up a website about the breach, which acknowledged 13 that at a minimum the driver’s license numbers and social security numbers of 14 Caesars Rewards members had been accessed and copied. (Id. at ¶ 228.) 15 B. Caesars’ Rewards Program 16 Caesars is one of the world’s largest lodging and gaming companies and 17 considers itself a global leader in gaming and hospitality. (Id. at ¶ 3.) Its loyalty 18 program, Caesars Rewards, allows members to earn credits by gambling or 19 staying at Caesars’ properties. (Id. at ¶¶ 3–4, 210.) Caesars requires that its 20 members provide highly sensitive PII such as their full legal name, full address, 21 date of birth, drivers’ license number, and social security number. (Id. at ¶ 212.) 22 Caesars’ 2023 Privacy Policy promises to “maintain physical, electronic and 23 organizational safeguards that reasonably and appropriately protect against the 24 loss, misuse, and alteration of the information under [their] control.” (Id. at ¶¶ 25 215, 239.)

27 been consolidated with this case, but the present motion concerns only Caesars. 28 (ECF No. 130.) 1 Caesars was aware that it faced a significant risk of cyberattacks well 2 before the August 2023 attack. (Id. at ¶¶ 250, 251.) Caesars told investors in 3 2022 that: “Compromises of our information systems or unauthorized access to 4 confidential information or our customers’ personal information could materially 5 harm our reputation and business.” (Id. at ¶ 250.) Plaintiffs allege that despite 6 knowing those risks, Caesars failed to adopt reasonable safeguards to protect 7 their PII. (Id. at ¶ 251.) 8 C. Plaintiffs’ Harm 9 Plaintiffs allege that as a result of the data breach, they have experienced 10 “actual and attempted fraud and/or have been exposed to an increased risk of 11 fraud, identity theft, and other misuse of their PII.” (Id. at ¶ 10.) They now closely 12 monitor their financial and other accounts to guard against fraud, which is 13 burdensome and time-consuming. (Id.) Plaintiffs also have already or will 14 purchase credit monitoring and other identity protection services, purchase 15 credit reports, place credit freezes and fraud alerts on their credit reports and 16 spend time investigating and disputing fraudulent or suspicious activity on their 17 accounts. (Id.) One Plaintiff has already spent $400 for a one-year subscription 18 for identity protection services. (Id. at 16.) Although Caesars offered to provide 19 credit monitoring to its loyalty program members, it has only agreed to provide 20 that service for 24 months. (Id. at ¶ 294.) 21 Several Plaintiffs have discovered that their PII was for sale on the dark 22 web following the data breach. (Id. at ¶¶ 6, 20, 41, 51, 61, 82, 92, 118, 140, 170, 23 191, 273.) Plaintiffs allege that this stolen PII can be used on its own or in 24 combination with personal information from other sources to create a package of 25 information capable of being used to commit further identity theft. (Id. at ¶ 11.) 26 Plaintiffs also allege that, had they known that the purchases at Caesars did not 27 include adequate data security, they would have paid less or not stayed at 28 1 Caesars hotels. (Id. at ¶ 290.) Plaintiffs also allege that the value of their PII has 2 diminished as a result of the data breach. (Id. at ¶¶ 276–85.) 3 D. Class Plaintiffs 4 There are nine proposed classes in this case: Nationwide Class; California 5 Subclass; Illinois Subclass; Indiana Subclass; Minnesota Subclass; New York 6 Subclass; Pennsylvania Subclass; Texas Subclass; and Virginia Subclass. (Id. at 7 ¶¶ 308, 312.) The Nationwide Class asserts claims against Caesars for negligence 8 (Count I), breach of implied contract (Count II), unjust enrichment (Count III), 9 and violation of the Nevada Consumer Fraud Act, Nev. Rev. Stat. § 41.600 (Count 10 IV). (Id. at ¶ 309.) The statewide subclasses assert statutory claims for violations 11 of various state data breach notification and consumer protection statutes. 12 (Counts V–XVIII). 13 E. Procedural History 14 Plaintiffs filed the initial class action complaint in this case in September 15 2023. (ECF No. 1.) Other lawsuits relating to the same data breach were 16 subsequently consolidated into this case. (ECF Nos. 21, 46, 55.) In July 2024, 17 Plaintiffs filed the Consolidated Class Action Complaint. (ECF No. 81.) Caesars 18 moves to dismiss all claims in that complaint. (ECF No. 91.) Also before the Court 19 is Plaintiffs’ motion for leave to file supplemental authorities in support of its 20 opposition to the motion to dismiss (ECF No. 114), which the Court grants and 21 considers in this order. 22 II. LEGAL STANDARD 23 A. Article III Standing 24 Under Rule 12(b)(1), a party may move to dismiss for lack of subject matter 25 jurisdiction. “[L]ack of Article III standing requires dismissal for lack of subject 26 matter jurisdiction under [Rule] 12(b)(1).” Maya v. Centex Corp., 658 F.3d 1060, 27 1067 (9th Cir. 2011). The “irreducible constitutional minimum” of standing 28 1 requires that a “plaintiff must have (1) suffered an injury in fact, (2) that is fairly 2 traceable to the challenged conduct of the defendant, and (3) that is likely to be 3 redressed by a favorable judicial decision.” Spokeo, Inc. v. Robins, 578 U.S. 330 4 (2016).

Free access — add to your briefcase to read the full text and ask questions with AI

Gill v. Caesars Entertainment, Inc., (D. Nev. 2025).

Gill v. Caesars Entertainment, Inc. (Gill v. Caesars Entertainment, Inc.) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Lujan v. Defenders of Wildlife
504 U.S. 555 (Supreme Court, 1992)
Bell Atlantic Corp. v. Twombly
550 U.S. 544 (Supreme Court, 2007)
Ashcroft v. Iqbal
556 U.S. 662 (Supreme Court, 2009)
Krottner v. Starbucks Corp.
628 F.3d 1139 (Ninth Circuit, 2010)
Maya v. Centex Corp.
658 F.3d 1060 (Ninth Circuit, 2011)
John Faulkner v. Adt Security Services, Inc.
706 F.3d 1017 (Ninth Circuit, 2013)
Clapper v. Amnesty International USA
133 S. Ct. 1138 (Supreme Court, 2013)
Antonio Hinojos v. Kohl's Corporation
718 F.3d 1098 (Ninth Circuit, 2013)
Smith v. Recrion Corporation
541 P.2d 663 (Nevada Supreme Court, 1975)
Leasepartners Corp. v. Robert L. Brooks Trust
942 P.2d 182 (Nevada Supreme Court, 1997)
Moss v. U.S. Secret Service
572 F.3d 962 (Ninth Circuit, 2009)
In Re Tobacco II Cases
207 P.3d 20 (California Supreme Court, 2009)
United States v. Crisona
440 F. Supp. 24 (S.D. New York, 1977)
Richardson v. U.S. Department of Interior
740 F. Supp. 15 (District of Columbia, 1990)
Stutman v. Chemical Bank
731 N.E.2d 608 (New York Court of Appeals, 2000)
Star Houston, Inc. v. Kundak
843 S.W.2d 294 (Court of Appeals of Texas, 1992)
Saini v. International Game Technology
434 F. Supp. 2d 913 (D. Nevada, 2006)
Betsinger v. D.R. Horton, Inc.
232 P.3d 433 (Nevada Supreme Court, 2010)
Sanchez Ex Rel. Sanchez v. Wal-Mart
221 P.3d 1276 (Nevada Supreme Court, 2009)
Lexmark Int'l, Inc. v. Static Control Components, Inc.
134 S. Ct. 1377 (Supreme Court, 2014)