Gill v. Caesars Entertainment, Inc.

District Court, D. Nevada·Decided August 15, 2025·No. 2:23-cv-01447·Unknown

Opinion

Case No. 2:23-cv-01447-ART-BNW In re: DATA BREACH SECURITY ORDER DENYING DEFENDANT’S MOTION TO DISMISS ENTERTAINMENT, INC. (ECF No. 91) This is a consolidated class action against Defendant Caesars Entertainment, Inc. (“Caesars”) relating to a data breach. In August 2023, Caesars’ Rewards member database was hacked, and Plaintiffs’ personal identifying information (“PII”) was accessed by hackers. Plaintiffs were members of Caesars’ rewards program and/or customers of Caesars’ gaming and entertainment services at the time. Plaintiffs bring a putative class action seeking redress for the harms they allegedly suffered from the data breach. (See ECF No. 81 (“Consolidated Class Action Complaint”).) Before the Court is Defendant’s motion to dismiss for lack of standing and failure to state a claim. (ECF No. 91.) For the following reasons, the Court finds that Plaintiffs have standing, and that Plaintiffs have plausibly pled each of their claims. Accordingly, Defendant’s motion to dismiss is denied. A. Summary of Allegations On or around August 18, 2023, members of the cybercriminal group Scattered Spider gained access to Caesars’ loyalty program database through a social engineering attack on Caesars’ IT support company.1 (ECF No. 81 at ¶¶ 2,

1 Plaintiffs’ lawsuit against that company, Coforge, Ltd. (“Coforge”), has since 224, 225.) The database contained sensitive PII, including names, drivers’ license numbers, and social security numbers of a “significant number” of Caesars’ loyalty program’s 65 million members. (ECF No. 81 at ¶ 1.) Caesars identified the suspicious activity on that day, yet Scattered Spider downloaded the PII five days later. (Id. at ¶ 225.) On September 7, 2023, Caesars’ interval investigation confirmed that Scattered Spider had acquired, among other data, a copy of its loyalty program database including names, driver’s license numbers, and social security numbers for “a significant number of Caesars Rewards’ tens of millions of members.” (Id. at ¶ 227.) On or around September 14, 2023, Caesars filed a Form 8-K with the SEC to alert investors and shareholders that the data breach had occurred. (Id. at ¶ 228.) Caesars also put up a website about the breach, which acknowledged that at a minimum the driver’s license numbers and social security numbers of Caesars Rewards members had been accessed and copied. (Id. at ¶ 228.) B. Caesars’ Rewards Program Caesars is one of the world’s largest lodging and gaming companies and considers itself a global leader in gaming and hospitality. (Id. at ¶ 3.) Its loyalty program, Caesars Rewards, allows members to earn credits by gambling or staying at Caesars’ properties. (Id. at ¶¶ 3–4, 210.) Caesars requires that its members provide highly sensitive PII such as their full legal name, full address, date of birth, drivers’ license number, and social security number. (Id. at ¶ 212.) Caesars’ 2023 Privacy Policy promises to “maintain physical, electronic and organizational safeguards that reasonably and appropriately protect against the loss, misuse, and alteration of the information under [their] control.” (Id. at ¶¶ 215, 239.)

been consolidated with this case, but the present motion concerns only Caesars. (ECF No. 130.) Caesars was aware that it faced a significant risk of cyberattacks well before the August 2023 attack. (Id. at ¶¶ 250, 251.) Caesars told investors in 2022 that: “Compromises of our information systems or unauthorized access to confidential information or our customers’ personal information could materially harm our reputation and business.” (Id. at ¶ 250.) Plaintiffs allege that despite knowing those risks, Caesars failed to adopt reasonable safeguards to protect their PII. (Id. at ¶ 251.) C. Plaintiffs’ Harm Plaintiffs allege that as a result of the data breach, they have experienced “actual and attempted fraud and/or have been exposed to an increased risk of fraud, identity theft, and other misuse of their PII.” (Id. at ¶ 10.) They now closely monitor their financial and other accounts to guard against fraud, which is burdensome and time-consuming. (Id.) Plaintiffs also have already or will purchase credit monitoring and other identity protection services, purchase credit reports, place credit freezes and fraud alerts on their credit reports and spend time investigating and disputing fraudulent or suspicious activity on their accounts. (Id.) One Plaintiff has already spent $400 for a one-year subscription for identity protection services. (Id. at 16.) Although Caesars offered to provide credit monitoring to its loyalty program members, it has only agreed to provide that service for 24 months. (Id. at ¶ 294.) Several Plaintiffs have discovered that their PII was for sale on the dark web following the data breach. (Id. at ¶¶ 6, 20, 41, 51, 61, 82, 92, 118, 140, 170, 191, 273.) Plaintiffs allege that this stolen PII can be used on its own or in combination with personal information from other sources to create a package of information capable of being used to commit further identity theft. (Id. at ¶ 11.) Plaintiffs also allege that, had they known that the purchases at Caesars did not include adequate data security, they would have paid less or not stayed at Caesars hotels. (Id. at ¶ 290.) Plaintiffs also allege that the value of their PII has diminished as a result of the data breach. (Id. at ¶¶ 276–85.) D. Class Plaintiffs There are nine proposed classes in this case: Nationwide Class; California Subclass; Illinois Subclass; Indiana Subclass; Minnesota Subclass; New York Subclass; Pennsylvania Subclass; Texas Subclass; and Virginia Subclass. (Id. at ¶¶ 308, 312.) The Nationwide Class asserts claims against Caesars for negligence (Count I), breach of implied contract (Count II), unjust enrichment (Count III), and violation of the Nevada Consumer Fraud Act, Nev. Rev. Stat. § 41.600 (Count IV). (Id. at ¶ 309.) The statewide subclasses assert statutory claims for violations of various state data breach notification and consumer protection statutes. (Counts V–XVIII). E. Procedural History Plaintiffs filed the initial class action complaint in this case in September 2023. (ECF No. 1.) Other lawsuits relating to the same data breach were subsequently consolidated into this case. (ECF Nos. 21, 46, 55.) In July 2024, Plaintiffs filed the Consolidated Class Action Complaint. (ECF No. 81.) Caesars moves to dismiss all claims in that complaint. (ECF No. 91.) Also before the Court is Plaintiffs’ motion for leave to file supplemental authorities in support of its opposition to the motion to dismiss (ECF No. 114), which the Court grants and considers in this order. A. Article III Standing Under Rule 12(b)(1), a party may move to dismiss for lack of subject matter jurisdiction. “[L]ack of Article III standing requires dismissal for lack of subject matter jurisdiction under [Rule] 12(b)(1).” Maya v. Centex Corp., 658 F.3d 1060, 1067 (9th Cir. 2011). The “irreducible constitutional minimum” of standing requires that a “plaintiff must have (1) suffered an injury in fact, (2) that is fairly traceable to the challenged conduct of the defendant, and (3) that is likely to be redressed by a favorable judicial decision.” Spokeo, Inc. v. Robins, 578 U.S. 330 (2016). Injury in fact requires “an invasion of a legally protected interest which is (a) concrete and particularized,” and “(b) ‘actual or imminent, not conjectural or hypothetical.’” Lujan v. Defenders of Wildlife, 504 U.S. 555, 560-61 (1992) (citations omitted). “The party invoking federal jurisdiction bears the burden of establishing these elements . . . with the manner and degree of evidence required at the successive stages of litigation.” Id. at 561. At the pleading stage,

Free access — add to your briefcase to read the full text and ask questions with AI

Gill v. Caesars Entertainment, Inc., (D. Nev. 2025).

Gill v. Caesars Entertainment, Inc. (Gill v. Caesars Entertainment, Inc.) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Lujan v. Defenders of Wildlife
504 U.S. 555 (Supreme Court, 1992)
Bell Atlantic Corp. v. Twombly
550 U.S. 544 (Supreme Court, 2007)
Ashcroft v. Iqbal
556 U.S. 662 (Supreme Court, 2009)
Krottner v. Starbucks Corp.
628 F.3d 1139 (Ninth Circuit, 2010)
Maya v. Centex Corp.
658 F.3d 1060 (Ninth Circuit, 2011)
John Faulkner v. Adt Security Services, Inc.
706 F.3d 1017 (Ninth Circuit, 2013)
Clapper v. Amnesty International USA
133 S. Ct. 1138 (Supreme Court, 2013)
Antonio Hinojos v. Kohl's Corporation
718 F.3d 1098 (Ninth Circuit, 2013)
Smith v. Recrion Corporation
541 P.2d 663 (Nevada Supreme Court, 1975)
Leasepartners Corp. v. Robert L. Brooks Trust
942 P.2d 182 (Nevada Supreme Court, 1997)
Moss v. U.S. Secret Service
572 F.3d 962 (Ninth Circuit, 2009)
In Re Tobacco II Cases
207 P.3d 20 (California Supreme Court, 2009)
United States v. Crisona
440 F. Supp. 24 (S.D. New York, 1977)
Richardson v. U.S. Department of Interior
740 F. Supp. 15 (District of Columbia, 1990)
Stutman v. Chemical Bank
731 N.E.2d 608 (New York Court of Appeals, 2000)
Star Houston, Inc. v. Kundak
843 S.W.2d 294 (Court of Appeals of Texas, 1992)
Saini v. International Game Technology
434 F. Supp. 2d 913 (D. Nevada, 2006)
Betsinger v. D.R. Horton, Inc.
232 P.3d 433 (Nevada Supreme Court, 2010)
Sanchez Ex Rel. Sanchez v. Wal-Mart
221 P.3d 1276 (Nevada Supreme Court, 2009)
Lexmark Int'l, Inc. v. Static Control Components, Inc.
134 S. Ct. 1377 (Supreme Court, 2014)