[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1kvxd7an1ke82":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":21,"affectedCount":21,"affectedCountStatus":22,"affectedCountLowerBound":23,"affectedCountUnit":24,"hasEnglishDescription":4,"severity":25,"dataClasses":26,"description":32,"seoTitle":33,"seoTitleEn":34,"seoDescription":33,"seoDescriptionEn":35,"logoUrl":36,"isVerified":4,"isSensitive":37,"isSpamList":37,"isMalware":37,"company":38},"68e3266eda11adda488252a5","MGM2022Update","MGM Resorts (2022 Update) Data Breach","mgm-resorts-2022-update","mgmresorts.com","2019-07-25T00:00:00.000Z","2022-05-29T01:43:46.000Z","2026-07-19T15:31:32.552Z","Hospitality guest data breach update","https:\u002F\u002Fwww.zdnet.com\u002Farticle\u002Fexclusive-details-of-10-6-million-of-mgm-hotel-guests-posted-on-a-hacking-forum\u002F",[15,17,18,19,20],"https:\u002F\u002Fwww.zdnet.com\u002Farticle\u002Fa-hacker-is-selling-details-of-142-million-mgm-hotel-guests-on-the-dark-web\u002F","https:\u002F\u002Fwww.vpnmentor.com\u002Fblog\u002Fcybersecurity\u002Fmgm-leaked-on-telegram\u002F","https:\u002F\u002Fsiliconangle.com\u002F2022\u002F05\u002F24\u002F142m-stolen-mgm-resort-records-publicly-shared-telegram\u002F","https:\u002F\u002Fwww.mgmresorts.com\u002F",24842001,"known",null,"unknown","Critical",[27,28,29,30,31],"Dates of birth","Email addresses","Names","Phone numbers","Physical addresses","\u003Cp>A larger dataset stemming from MGM Resorts' 2019 breach resurfaced in 2022 with 24,842,001 unique email addresses. This superset, containing approximately 142 million raw rows, is broader than the first MGM Resorts record with 3,081,321 unique emails. Raw-row volume is not a count of unique people because one person may have multiple reservation or contact records. This page does not cover the separate MGM Resorts cyber incident disclosed in 2023.\u003C\u002Fp>\n\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\n\u003Cp>The verified data classes are dates of birth, email addresses, names, phone numbers, and physical addresses. Combining these fields increases the risk of personalized phishing, fake reservation or cancellation messages, call-center scams, and abuse of account recovery. A phone number and email address in the same profile allow attackers to try SMS and email together, while a matching birth date and address can make identity-verification stories more convincing. \u003Cstrong>Passwords, payment cards, and bank accounts are not verified data classes for this record.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\n\u003Cp>The canonical breach date is July 25, 2019. MGM Resorts said it detected unauthorized access to a cloud server containing a limited amount of guest information in the summer of 2019 and notified affected individuals. In February 2020, 10.6 million guest rows were published; 3,081,321 unique email addresses were verified in that first copy. A larger dataset advertised in July 2020 claimed to contain 142,479,937 guest records, and four archives totaling about 8 GB were shared widely in May 2022. Analysis verified 24,842,001 unique email addresses in this superset and found it highly likely that the data came from the same 2019 incident. \u003Cstrong>Approximately 142 million raw rows and 24,842,001 unique email addresses are different measures.\u003C\u002Fstrong> The detailed method of unauthorized access beyond the cloud server was not publicly disclosed.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>People whose contact information appeared in MGM Resorts guest records extending back to 2017 and earlier are at risk. Those who still use the same phone number or physical address, business travelers who booked with corporate email, and people with a public profile may receive more convincing targeted messages. Combining a name, date of birth, address, and phone number can help an attacker pose as a hotel or travel service. Appearing in the dataset does not mean an active MGM account was taken over or that financial information was exposed.\u003C\u002Fp>\n\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\n\u003Cp>Treat unexpected emails, text messages, and calls claiming to be from MGM Resorts, a hotel reservation service, a loyalty program, or a travel agency with caution. Open the official website or application yourself instead of following message links, and verify calls requesting reservation changes, payment, or identity details by calling a published number. Enable multi-factor authentication on your email account, then review active sessions and recovery options. Although passwords were not verified in this breach, use a unique password for every travel and loyalty account, and never give a security code or extra identity details to someone who already knows your contact information.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>Hard-to-change details such as names, birth dates, phone numbers, and addresses can support social engineering years later. Separating travel accounts with dedicated email aliases, generating a unique password for each account with a password manager, and removing unnecessary profile fields can reduce long-term exposure. Keep login alerts enabled for financial and email accounts, and regularly replace recovery options that reference an old phone number or address. People who book travel with a work email should report suspicious MGM- or hotel-themed messages to their organization's security team.\u003C\u002Fp>\n\u003Ch2>Check Your Data\u003C\u002Fh2>\n\u003Cp>Check this record with the email address you used with MGM Resorts. \u003Cstrong>A match means your address appears in the larger MGM dataset circulated in 2022; it does not mean all 142 million rows represented unique people.\u003C\u002Fstrong> If the result is positive, prioritize your email account, travel profiles, and important accounts that use the same contact details. If the result is negative, remember that it applies only to this dataset and that the first MGM Resorts record should be checked separately.\u003C\u002Fp>","","MGM Resorts (2022 Update) Data Breach (24.8 Million Reported Records)","MGM Resorts (2022 Update) Data Breach. 24.8 Million reported records were reported. Reported data: Dates of birth, Email addresses, Names. Review the scope…","\u002Fuploads\u002Flogo\u002Fmgmresorts_com.webp",false,{"name":39,"sector":40,"country":41,"website":10,"websiteArchiveUrl":33,"websiteStatus":33,"websiteCheckedAt":23},"MGM Resorts","Hospitality \u002F Casino Resorts","United States"]