Data breach
MGM Resorts
- Records
- 10,632,809
- Breach date
- 25 July 2019Estimated
- Added
- 1 December 2024
What was exposed
4 types of data · 1 more reported
- Names10,632,575
- Home addresses5,805,533
- Phone numbers4,276,773
- Email addresses3,171,327
- Dates of birthReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In July 2019, an unauthorized person gained access to a cloud server operated by MGM Resorts International and obtained the personal details of a large batch of former hotel guests. According to our investigation team, this listing contains records for about 10.6 million individuals. The data circulated in private hacking circles before a batch was posted publicly on a hacking forum in February 2020, a dump that ZDNet verified at the time. Reporting later that year suggested the total number of affected guests was far larger, and the records have resurfaced repeatedly since.
July 2019: MGM discovered unauthorized access to a cloud server containing information about certain previous guests, according to statements the company later gave to ZDNet. Threat intelligence firm KELA told ZDNet the data had been circulating in private hacking circles since at least that month.
February 2020: Personal details of roughly 10.6 million former MGM hotel guests were posted as a free download on a hacking forum. ZDNet verified the data and MGM confirmed it stemmed from the 2019 incident.
July 2020: ZDNet reported that a hacker was offering the details of more than 142 million MGM guests for sale on a dark web marketplace for just over $2,900.
June 18, 2025: A federal judge granted final approval of a $45 million settlement resolving consolidated litigation against MGM over the 2019 breach and a separate 2023 incident, according to the law firm Cohen Milstein.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Email: about 3.2 million records
Phone Number: about 4.3 million records
Name: about 10.6 million records
Home Address: about 5.8 million records
Reporting by ZDNet, confirmed by MGM, indicates the leaked files also included dates of birth. The company said at the time that no financial, payment card, or password data was involved, and that Social Security numbers and reservation details were not part of the exposed information.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
This breach did not expose passwords or payment data, but the combination of names, home addresses, phone numbers, and birth dates is valuable to criminals in other ways.
Targeted phishing and scams: Scammers can use real names, addresses, and birth dates to craft convincing emails, calls, or text messages that appear legitimate.
SIM swapping: Phone numbers paired with birth dates can help attackers convince a mobile carrier to transfer your number to a device they control, which can compromise accounts that rely on text-message verification.
Identity verification abuse: Birth dates and addresses are common answers to security questions and can support fraudulent account openings or impersonation.
ZDNet, working with security researchers, called some past guests whose details appeared in the dump and found many phone numbers were still valid.
What Is MGM Resorts Doing in Response?
MGM confirmed the breach in February 2020 after the first public dump appeared. A spokesperson told ZDNet that the company discovered the unauthorized access to a cloud server the previous summer, was confident no financial, payment card, or password data was involved, and said it promptly notified impacted guests in accordance with state laws. MGM did not publicly announce the breach before the data surfaced. The company later said the incident had been addressed and that it continues to strengthen security measures protecting guest data. The class action settlement approved in June 2025 provides cash payments and a year of financial account monitoring for eligible U.S. residents.
What Should You Do If You Were Affected?
Be skeptical of unexpected contact. Anyone calling, emailing, or texting you with accurate personal details may have obtained them from this breach. Verify claims independently before responding.
Consider a SIM swap PIN. Ask your mobile carrier to add a port-out PIN or account lock so your number cannot be transferred without your consent.
Guard your accounts. Use strong, unique passwords and prefer app-based two-factor authentication over text-message codes where possible.
Watch your mail and credit. Monitor bank and credit card statements for unfamiliar activity. You can request free credit reports and consider a fraud alert or credit freeze with the major credit bureaus.
Check the settlement. If your data was part of the 2019 breach, the approved settlement may provide compensation.
In the news
- ZDNet: Details of 10.6 million MGM hotel guests posted on a hacking forumzdnet.com (opens in a new tab)
- ZDNet: A hacker is selling details of 142 million MGM hotel guests on the dark webzdnet.com (opens in a new tab)
- Cohen Milstein: In re MGM Resorts International Data Breach Litigationcohenmilstein.com (opens in a new tab)
- Sophos: Data of 10.6m MGM hotel guests posted for sale on Dark Web forumsophos.com (opens in a new tab)
