[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fotmpbofw71d1":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":22,"affectedCountUnit":23,"hasEnglishDescription":4,"severity":24,"dataClasses":25,"description":31,"seoTitle":32,"seoTitleEn":33,"seoDescription":32,"seoDescriptionEn":34,"logoUrl":35,"isVerified":4,"isSensitive":36,"isSpamList":36,"isMalware":36,"company":37},"68e3266eda11adda488252a8","mgm","MGM Resorts Data Breach","mgm-resorts","mgmresorts.com","2019-07-25T00:00:00.000Z","2020-02-20T00:52:55.000Z","2020-02-20T01:00:57.000Z","2026-07-18T23:54:14.228Z","Hospitality guest data breach","https:\u002F\u002Fwww.priv.gc.ca\u002Fen\u002Fopc-actions-and-decisions\u002Finvestigations\u002Finvestigations-into-businesses\u002F2022\u002Fpipeda-2022-004\u002F",[16,18,19],"https:\u002F\u002Fwww.axios.com\u002F2020\u002F02\u002F20\u002Fmgm-hack-10-million-guests-data-exposed-report","https:\u002F\u002Fwww.mgmresorts.com\u002F",3081321,"known",null,"unknown","Critical",[26,27,28,29,30],"Dates of birth","Email addresses","Names","Phone numbers","Physical addresses","\u003Cp>The MGM Resorts data breach is a large-scale hotel and casino customer data incident affecting MGM Resorts International guest data on July 25, 2019, associated with 3,081,321 unique email addresses. The initial record is based on a dataset containing 10.6 million guest rows, with some records dating back to 2017. Confirmed data classes include birth dates, email addresses, full name information, phone numbers, and physical addresses. This record should not be presented as containing password, payment card, bank account, or government ID data.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>Although the data revealed in this record does not directly include account passwords, it forms a strong combination in terms of identifying the individual and targeted fraud. When full name, email address, phone number, physical address, and date of birth are considered together, an attacker could prepare messages that appear personal, such as hotel reservations, loyalty program notifications, payment confirmations, room upgrades, refunds, or travel plans. Since guest communication in accommodation and entertainment brands like MGM Resorts is multi-channel, the risk of social engineering increases via email, SMS, and phone calls.\u003C\u002Fp>\n\u003Cp>Date of birth and address information can be used to match a person's identity with other sources. A phone number provides direct contact for a fake support call or message. A physical address gives additional context for personal profiling and targeted advertising\u002Ffraud. Therefore, the risk is not limited to spam; scenarios such as phishing, fake reservation notices, loyalty account fraud, and personal data aggregation come to the forefront. However, password or payment card leak claims should not be conveyed to the user for this record.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>Verified scope; includes the domain mgmresorts.com, the breach date of July 25, 2019, the addition date of February 20, 2020, 3,081,321 unique email addresses, and 10.6 million guest records. It is stated that the dataset is associated with one of the cloud services used by MGM Resorts, was later distributed on a forum, and was reshared through different sources. A larger superset, considered to be linked to the same incident, was also monitored in 2022; therefore, the initial MGM Resorts record should not be confused with the 2022 superset count.\u003C\u002Fp>\n\u003Cp>Credit card, bank account, password, social security number, passport, or driver's license fields should not be added to this record. Although certain official audits mention types of identification numbers for specific subgroups, for a user-facing open record, verified standard data classes are limited to date of birth, email, full name, phone number, and physical address. MGM Resorts is a company in the hotel, casino, accommodation, and entertainment industry; therefore, keeping the industry field as general technology would be misleading. The country field can be retained as the United States.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The highest risk lies with guests who have stayed at MGM Resorts properties, made a reservation, used a loyalty account, or contacted the brand via email\u002Fphone. A combination of name, address, phone number, and date of birth that can be associated with travel history can make fraud messages that appear personalized more convincing. The risk may increase for individuals using MGM properties for business travel due to the link between corporate email addresses and private accommodation information.\u003C\u002Fp>\n\u003Cp>People whose phone number and email address are available at the same time can be targeted with fake reservation confirmations, loyalty point notifications, casino promotions, accommodation refunds, or payment verification requests. For users whose physical address is also available, personal information used in identity verification questions may become predictable. Since this record does not contain a password, the assumption of direct account takeover is not accurate; however, attempting to obtain a password or payment information from the user through phishing and social engineering messages is a realistic risk.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>Users who see MGM Resorts matches should first carefully review reservation, refund, payment, loyalty points, or promotion messages received via email and phone. Instead of logging in through the link in the message, they should go directly to the relevant service from the address bar. If personal information such as date of birth, address, payment information, verification code, or card details is requested during a phone call, the conversation should be ended and checked through the official communication channel.\u003C\u002Fp>\n\u003Cp>Although the password is not a verified data class in this record, the email account should be protected. A strong and unique password should be used for the email account, two-step verification should be enabled, and unknown sessions should be closed. For MGM Rewards or similar travel\u002Floyalty accounts, security notifications and registered phone and email information should be reviewed. Credit card or bank data is not a verified part of this record; nevertheless, suspicious booking and payment notifications should be checked through official channels.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>Accommodation, travel, and loyalty programs require long-term privacy management because they collect communication and address data as well as identity information. Users should delete unnecessary old addresses from hotel and travel accounts, close loyalty accounts that are no longer in use, and keep personal and work emails separate whenever possible. Using a separate email address for promotional and reservation messages from travel brands can make it easier to identify risky messages.\u003C\u002Fp>\n\u003Cp>From a company perspective, this incident shows that guest data is not just marketing data. Cloud services, developer accesses, temporary access keys, and external service accounts should be strictly audited; least privilege, multi-factor authentication, and rapid breach assessment should become standard. When guest data is exposed, the notification process should not be delayed, and it should be clearly stated which areas were affected and which were not. Data minimization and timely notification are as important as technical measures for maintaining trust.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>If you see a match for MGM Resorts on LeakData, consider this as a 2019 hotel and casino guest data breach. The match indicates that your email address, full name, phone number, physical address, and date of birth may have been included in this record. This does not mean that your password or payment card information was exposed. The main action is to verify travel and reservation-related messages you receive, protect your email account, and review your loyalty account information.\u003C\u002Fp>\n\u003Cp>If you receive a suspicious message about a reservation, refund, points usage, room upgrade, or payment verification, check through the official site or call center without clicking the link. Messages personalized with information such as date of birth and address can also be fake. Users registered with a work email should inform the corporate security team and be cautious of travel-themed phishing messages received in their work account. The lesson for organizations is also clear: personal data used in employees' travel and loyalty accounts can be an entry point for targeted email attacks.\u003C\u002Fp>","","MGM Resorts Data Breach (3.1 Million Reported Records)","MGM Resorts Data Breach. 3.1 Million reported records were reported. Reported data: Dates of birth, Email addresses, Names. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fmgmresorts_com.webp",false,{"name":38,"sector":39,"country":40,"website":10,"websiteArchiveUrl":32,"websiteStatus":32,"websiteCheckedAt":22},"MGM Resorts","Hospitality \u002F Casino Resorts","United States"]