MalwareRansomwareBlackCatData ExfiltratedData EncryptedCustomer Data InvolvedTargetedMulti-Stage ChainPIIIDENTITY_BASICIDENTITY_GOVERNMENTCriticalContained
MGM RESORTS INTERNATIONAL
bd_a165e7cc6b9dc225 · schema v1 · pii pii-v1
Full breach record for MGM RESORTS INTERNATIONAL →MGM Resorts International disclosed a September 2023 ransomware attack by the BlackCat group, affecting approximately 37 million individuals. The incident involved the encryption of data and exfiltration of customer PII, including names, addresses, and for some, SSNs and passport numbers. MGM engaged forensic investigators, notified law enforcement, and provided credit monitoring to affected individuals. The South Carolina Attorney General received a breach notice on October 5, 2023.
This filing is one of 12 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_05c59c84e811817fWashington State AGfiled 2023-10-05(1d gap)Candidate
- bd_25f570b90148b65eOregon State AGfiled 2023-10-05(1d gap)Verified
- bd_2cf9544a4111fecbVermont State AGfiled 2023-10-05(1d gap)Verified
- bd_36e2c8e1303bff37Delaware State AGfiled 2023-10-05(1d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 60d gap
- bd_4e28f4a3e508d542Maine State AGfiled 2023-10-05(1d gap)Verified
- bd_65dbfae801fc66abDelaware State AGfiled 2023-10-05(1d gap)Verified
- bd_6bbbeaea01c0cd31SEC 8-Kfiled 2023-10-05(1d gap)Verified
- bd_e80691128547fd2dDelaware State AGfiled 2023-10-05(1d gap)Verified
- bd_ee40948044b421adMontana State AGfiled 2023-10-05(1d gap)Verified
- bd_0171facdc96060a9California State AGfiled 2023-12-05(60d gap)Verified
Showing first 10 of 11 linked disclosures.
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Security%20Breach%20Notices/MGMResortsInternational.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 6, 2023
- Raw hash
- 2f43d7e283526ef4b29e6ac23234bc5735d7e5dcc5360bba70925a97742c8585
Reporting entity
- Name
- MGM RESORTS INTERNATIONALnorm: mgm resorts
- Domain
- mgmresorts.com
Victim entity
- Name
- MGM RESORTS INTERNATIONALnorm: mgm resorts
- Domain
- mgmresorts.com
Incident
- Discovered
- Sep 9, 2023
- Materiality determined
- Oct 5, 2023
- Notification sent
- Oct 5, 2023
- Affected individuals
- 37,000,000
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware· BlackCat
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 ChannelT1190 Exploit Public-Facing Application
- Threat actor
- BlackCatExternalFinancial
- Regulator citations
- Notified South Carolina Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 27 days(27 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.