DisclosureLens
HackingHospitalityHospitalityStolen CredentialsCustomer Data InvolvedTargetedIdentity (basic)Government IDPIIMediumContained

MGM RESORTS INTERNATIONAL

bd_ee40948044b421ad · schema v1 · pii pii-v1

Severity

Medium

Discovered

Sep 29, 2023

Filed

Oct 5, 2023

To disclose

6 days

Affected

1state residents only

Linked

14 filings

Confidence

65%
Full breach record for MGM RESORTS INTERNATIONAL4 incidents on file

MGM Resorts International disclosed that an unauthorized third party obtained customer personal information on September 11, 2023. The company determined this on September 29, 2023. Affected data included names, contact info, DOB, driver's license numbers, and for some, SSNs and passport numbers. MGM shut down systems, engaged cybersecurity experts, coordinated with law enforcement, and offered credit monitoring.

Incident timeline

undetected · 18 days
discovery → filing · 6 days

Sep 11, 2023

Begins

Sep 29, 2023

Discovered

Oct 5, 2023

Filed

This filing is one of 14 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (10) · sorted by filing gap

Show 6 more filingsup to 61d gap

Showing first 10 of 13 linked disclosures.

Filing propagation · 11 filings · 10 states

View merged incident ↗
Washington State AGOct 5 · first
Oregon State AGOct 5 · first
Vermont State AGOct 5 · first
Indiana State AGOct 5 · first
Maine State AGOct 5 · first
Delaware State AGOct 5 · first
SEC 8-KOct 5 · first
Montana State AGOct 5 · first · this page

Pattern: first filing Oct 5 (WA), last Dec 5 (CA) — a 61-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Cascade drawn from the first 10 linked disclosures of 13 — the full spread may be wider.

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.