MGM RESORTS INTERNATIONAL
bd_f7c35a0d4803f35c · schema v1 · pii pii-v1
Full breach record for MGM RESORTS INTERNATIONAL →MGM Resorts International disclosed that an unauthorized third party obtained personal information of some customers on September 11, 2023. The breach window was identified as September 8-12, 2023. Affected data included names, contact information, gender, date of birth, Social Security numbers, and driver's license numbers. For a limited number of customers, passport numbers were also affected. Passwords, bank account numbers, and payment card information were not believed to be affected. MGM shut down certain systems, engaged cybersecurity experts, coordinated with law enforcement, and offered credit monitoring.
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_05c59c84e811817fWashington State AGfiled 2023-10-05Candidate
- bd_25f570b90148b65eOregon State AGfiled 2023-10-05Verified
- bd_2cf9544a4111fecbVermont State AGfiled 2023-10-05Verified
- bd_36e2c8e1303bff37Delaware State AGfiled 2023-10-05Verified
Show 6 more filings ↓Show fewer ↑up to 61d gap
- bd_4e28f4a3e508d542Maine State AGfiled 2023-10-05Verified
- bd_65dbfae801fc66abDelaware State AGfiled 2023-10-05Verified
- bd_6bbbeaea01c0cd31SEC 8-Kfiled 2023-10-05Verified
- bd_e80691128547fd2dDelaware State AGfiled 2023-10-05Verified
- bd_a165e7cc6b9dc225South Carolina State AGBlackCatfiled 2023-10-06(1d gap)Verified
- bd_0171facdc96060a9California State AGfiled 2023-12-05(61d gap)Verified
Showing first 10 of 11 linked disclosures.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-574721
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 5, 2023
- Raw hash
- 12a8143c515118f37ee53f60f47b5f7ca2e1b1ed792ec677e45d29d7c758b5db
Reporting entity
- Name
- MGM RESORTS INTERNATIONALnorm: mgm resorts
Victim entity
- Name
- MGM RESORTS INTERNATIONALnorm: mgm resorts
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.