HackingStolen CredentialsData EncryptedCustomer Data InvolvedDownstream VictimsPIIIDENTITY_GOVERNMENTMediumContained
WYNN RESORTS, LIMITED
bd_9faa773311b20809 · schema v1 · pii pii-v1
Full breach record for WYNN RESORTS, LIMITED →Wynn Resorts, Limited notified the Maine Attorney General of an external system breach (hacking) discovered on February 20, 2026, impacting 5 Maine residents. The breach occurred in October 2025 on HR systems, affecting employee data. No evidence of identity theft found, but Kroll was engaged to provide 24 months of credit monitoring and identity theft services.
Maine clockDiscovered Feb 20, 2026 → Filed with AG Apr 3, 202642d ⏱ ME AG >30d6 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_1a6e76fd41bc08a9New Hampshire State AGfiled 2026-04-03Verified
- bd_1e52a6a54affd92fIndiana State AGfiled 2026-04-03Candidate
- bd_83603f97a9b77d76Indiana State AGfiled 2026-04-03Candidate
- bd_9e9a13e678e1b2c2Vermont State AGfiled 2026-04-03Verified
Show 1 more filing ↓Show fewer ↑up to 3d gap
- bd_e2d7f5d9f01691c5Texas State AGfiled 2026-04-06(3d gap)Verified by operator
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/19665e25-633d-4d23-983c-5aad0784b605.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 3, 2026
- Raw hash
- ce8c5ddac09607532d1b60dc76d47768f9f5f5341d6dbb711c2ec49e8a711965
Reporting entity
- Name
- WYNN RESORTS, LIMITEDnorm: wynn resorts
- Domain
- wynnresorts.com
- Industry
- hospitality
Victim entity
- Name
- WYNN RESORTS, LIMITEDnorm: wynn resorts
- Domain
- wynnresorts.com
- Industry
- hospitality
Incident
- Discovered
- Feb 20, 2026
- Materiality determined
- Feb 20, 2026
- Notification sent
- Apr 3, 2026
- Affected individuals
- 5
- Data types
- PIIIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1486 Data Encrypted for Impact
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 6 weeks(42 days from discovery to filing)
- Compliance flags
- ME AG >30d · 42d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Feb 20, 2026→ Filed with AG: Apr 3, 202642d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.