MGM RESORTS INTERNATIONAL
ent_019e221aa2ec23d8e3aa5700b9e33b7c
Disclosures
18
State AG · SEC 8-K · Leak Site · 14 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
1,857,761
as filed · State AG WA
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- MGM RESORTS INTERNATIONAL
- Normalized
- mgm resorts— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 54930066VBP7DZEGGJ87
- SEC EDGAR CIK
- 0000789570
- Domain
- mgmresorts.com
Disclosure history (18)newest first
- Massachusetts State AGas victim2026-03-07
MGM Resorts International notified Massachusetts residents of a data incident. The notice offers 24 months of complimentary Experian IdentityWorks credit monitoring and identity restoration services. The provided document excerpt does not contain details regarding the nature of the breach, dates of occurrence or discovery, specific data types compromised, or the number of individuals affected.
- California State AGas victim2023-12-05
MGM Resorts International disclosed that an unauthorized third party obtained personal information of some customers on September 11, 2023. The breach window is listed as September 8-12, 2023. Affected data includes names, contact info, gender, date of birth, and driver's license numbers; for a limited number of customers, Social Security and passport numbers were also affected. Passwords, bank accounts, and payment card information were not affected. MGM shut down systems, engaged cybersecurity experts, and is offering credit monitoring.
- South Carolina State AGas victim2023-10-06
MGM Resorts International notified South Carolina that an unauthorized third party obtained customer personal information on September 11, 2023. Data included names, contact info, DOB, driver's license, and for some, SSN/passport. MGM shut down systems, engaged cybersecurity experts, coordinated with law enforcement, and offered credit monitoring.
- Washington State AGas victim2023-10-05
MGM Resorts International filed a supplemental notice with the Washington AG regarding a cybersecurity incident. Unauthorized access occurred on September 11, 2023, discovered on September 29, 2023. The incident affected 1,857,761 Washington residents, exposing names, contact info, DOB, driver's licenses, and SSNs/passports. MGM engaged forensic experts, coordinated with law enforcement, and provided credit monitoring.
- Oregon State AGas victim2023-10-05
MGM Resorts International reported a data breach to the Oregon Attorney General. The breach was reported on 2023-10-05. The breach occurred during 9/8/2023 - 9/12/2023. The breach was discovered on 9/8/2023. 0 individuals were affected. Notice was sent on 10/5/2023.
- Vermont State AGas victim2023-10-05
MGM Resorts International notified consumers of a data breach involving unauthorized access to systems. The incident compromised personal information including names, Social Security numbers, and dates of birth. MGM engaged cybersecurity experts, coordinated with law enforcement, and provided two years of complimentary credit monitoring and identity protection services through Experian to affected individuals.
- Massachusetts State AGas victim2023-10-05
MGM Resorts International reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-10-05. 313,400 Massachusetts residents were affected. The report records the breach type as electronic.
- Indiana State AGas victim2023-10-05
MGM Resorts International reported a data breach to the Indiana Attorney General. The breach occurred on 2023-09-08 and was reported on 2023-10-05.
- Maine State AGas victim2023-10-05
MGM Resorts International filed a notice regarding an external system breach (hacking) that occurred from September 8 to September 12, 2023, and was discovered on September 8, 2023. The breach compromised personal identifiers, including names and driver's license or non-driver identification card numbers. While the filing indicates zero Maine residents were affected, the company offered credit monitoring and identity protection services through Experian.
- Delaware State AGas victim2023-10-05
MGM Resorts International notified Delaware and other state attorneys general of a cybersecurity incident involving unauthorized access to systems. The company shut down systems, engaged cybersecurity experts, and coordinated with law enforcement. Affected individuals were offered two years of complimentary credit monitoring and identity protection services through Experian. The incident involved personal information, including Social Security numbers.
- FEDERALSEC 8-Kas victim2023-10-05
MGM Resorts International disclosed a cybersecurity incident detected on September 12, 2023. Criminal actors obtained personal information (names, contact info, DOB, driver's license numbers) and, for a limited number of customers, Social Security and passport numbers, for transactions prior to March 2019. The company shut down systems to contain the breach, preventing access to payment card data. Estimated negative impact on Q3 Adjusted Property EBITDAR is ~$100 million. Investigation is ongoing but activity is contained.
- Montana State AGas victim2023-10-05
MGM Resorts International disclosed that an unauthorized third party obtained customer personal information on September 11, 2023. The company determined this on September 29, 2023. Affected data included names, contact info, DOB, driver's license numbers, and for some, SSNs and passport numbers. MGM shut down systems, engaged cybersecurity experts, coordinated with law enforcement, and offered credit monitoring.
- California State AGas victim2023-10-05
MGM Resorts International disclosed that an unauthorized third party obtained personal information of some customers on September 11, 2023. The breach window was identified as September 8-12, 2023. Affected data included names, contact information, gender, date of birth, Social Security numbers, and driver's license numbers. For a limited number of customers, passport numbers were also affected. Passwords, bank account numbers, and payment card information were not believed to be affected. MGM shut down certain systems, engaged cybersecurity experts, coordinated with law enforcement, and offered credit monitoring.
- GLOBALLeak Siteas victim2023-09-14
MGM Resorts International is an American global hospitality and entertainment company.
- FEDERALSEC 8-Kas victim2023-09-13
MGM Resorts International filed an 8-K on September 13, 2023, reporting a cybersecurity issue disclosed via press release on September 12, 2023. The filing provides no details on the nature of the incident, data types affected, or number of individuals impacted.
- Illinois State AGas victim2023-01-01
MGM RESORTS INTERNATIONAL filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-702). The register records the breach as discovered on September 11, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Montana State AGas victim2019-09-05
MGM Resorts International notified Montana residents of a July 7, 2019 data incident where an unauthorized individual accessed the network, downloaded customer names and driver's license numbers, and posted them on a closed forum. MGM reported to law enforcement and offered 12 months of credit monitoring.
- New Hampshire State AGas victim2019-09-04
MGM Resorts International notified the NH AG that an unauthorized individual accessed its internal system on July 7, 2019, using a compromised third-party integration account. The actor exfiltrated data including names, addresses, phone numbers, and NH driver's license numbers. Data was posted on a closed forum for sale and removed on July 24. 7 NH residents affected. MGM engaged forensic firms, notified law enforcement, and offered credit monitoring.
Subsidiary disclosures (1)filed by group companies
◈ These filings were made by or about subsidiaries of MGM RESORTS INTERNATIONAL — not by MGM RESORTS INTERNATIONAL itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.