MGM RESORTS INTERNATIONAL
ent_019e221aa2ec23d8e3aa5700b9e33b7c
Disclosures
15
SEC 10-K Item 1C · State AG · SEC 8-K · 9 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
37,000,000
nationwide · State AG SC
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- MGM RESORTS INTERNATIONAL
- Normalized
- mgm resorts— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 54930066VBP7DZEGGJ87
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (15)newest first
- FEDERALSEC 10-K Item 1Cas victim2026-02-11
The Company discloses a past cybersecurity incident from September 2023 in its 10-K Item 1C. The incident is referred to as the 'Cybersecurity Issue.' The Company states it does not believe past incidents have materially affected its financial condition, though no guarantee exists for future impacts. The filing details robust cybersecurity governance, including an Audit Committee overseeing risk, a CISO reporting to the CTO, annual external assessments, and employee training. No specific details on the nature, scope, or data types of the September 2023 incident are provided beyond the name.
- 🐻California State AGas victim2023-12-05
MGM Resorts International disclosed that an unauthorized third party obtained personal information of some customers on September 11, 2023. The breach window is listed as September 8-12, 2023. Affected data includes names, contact info, gender, date of birth, and driver's license numbers; for a limited number of customers, Social Security and passport numbers were also affected. Passwords, bank accounts, and payment card information were not affected. MGM shut down systems, engaged cybersecurity experts, and is offering credit monitoring.
- 🌴South Carolina State AGas victim2023-10-06
MGM Resorts International disclosed a September 2023 ransomware attack by the BlackCat group, affecting approximately 37 million individuals. The incident involved the encryption of data and exfiltration of customer PII, including names, addresses, and for some, SSNs and passport numbers. MGM engaged forensic investigators, notified law enforcement, and provided credit monitoring to affected individuals. The South Carolina Attorney General received a breach notice on October 5, 2023.
- 🌲Washington State AGas victim2023-10-05
MGM Resorts International, a business sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2023-09-08 and filed notice on 2023-10-05. 811,740 Washington residents were affected. 27 days elapsed between awareness and notification. 0 days to identify the breach. 4 days to contain the breach.
- 🦫Oregon State AGas victim2023-10-05
MGM Resorts International reported a data breach to the Oregon Attorney General. The breach was reported on 2023-10-05. The breach occurred during 9/8/2023 - 9/12/2023. The breach was discovered on 9/8/2023. 0 individuals were affected. Notice was sent on 10/5/2023.
- 🍁Vermont State AGas victim2023-10-05
MGM Resorts International notified consumers of a data breach involving unauthorized access to systems. The incident compromised personal information including names, Social Security numbers, and dates of birth. MGM engaged cybersecurity experts, coordinated with law enforcement, and provided two years of complimentary credit monitoring and identity protection services through Experian to affected individuals.
- 💎Delaware State AGas victim2023-10-05
MGM Resorts International issued a state-AG breach notification to residents of multiple jurisdictions (including Delaware, Iowa, Maryland, Massachusetts, New Mexico, Oregon, Rhode Island, and D.C.). The company shut down systems, engaged cybersecurity experts, and coordinated with law enforcement. Affected individuals were offered 24 months of complimentary credit monitoring and identity protection through Experian. The notification references identity theft and fraud but does not specify the exact data types or number of affected individuals.
- 🦞Maine State AGas victim2023-10-05
MGM Resorts International filed a notice regarding an external system breach (hacking) that occurred from September 8 to September 12, 2023, and was discovered on September 8, 2023. The breach compromised personal identifiers, including names and driver's license or non-driver identification card numbers. While the filing indicates zero Maine residents were affected, the company offered credit monitoring and identity protection services through Experian.
- 💎Delaware State AGas victim2023-10-05
MGM Resorts International notified Delaware and other state attorneys general of a cybersecurity incident involving unauthorized access to systems. The company shut down systems, engaged cybersecurity experts, and coordinated with law enforcement. Affected individuals were offered two years of complimentary credit monitoring and identity protection services through Experian. The incident involved personal information, including Social Security numbers.
- FEDERALSEC 8-Kas victim2023-10-05
MGM Resorts International disclosed a cybersecurity incident identified on September 12, 2023. Criminal actors accessed customer data including names, contact info, driver's license numbers, and for some, SSNs and passports. Data dates back to March 2019. The incident was contained, systems restored, and free credit monitoring offered. Estimated financial impact is ~$100M in Q3 2023 EBITDAR.
- 💎Delaware State AGas victim2023-10-05
MGM Resorts International disclosed a cybersecurity incident affecting customer systems. An unauthorized third party obtained personal information (names, contact info, DOB, driver's license, SSN, passport) starting September 11, 2023. MGM shut down systems, engaged cybersecurity experts, coordinated with law enforcement, and offered credit monitoring. Investigation was ongoing as of October 5, 2023.
- 🦬Montana State AGas victim2023-10-05
MGM Resorts International reported a data breach to the Montana Attorney General. The breach was reported on 2023-10-05. The breach occurred on 9/11/2023. 1 Montana residents were affected.
- 🐻California State AGas victim2023-10-05
MGM Resorts International disclosed that an unauthorized third party obtained personal information of some customers on September 11, 2023. The breach window was identified as September 8-12, 2023. Affected data included names, contact information, gender, date of birth, Social Security numbers, and driver's license numbers. For a limited number of customers, passport numbers were also affected. Passwords, bank account numbers, and payment card information were not believed to be affected. MGM shut down certain systems, engaged cybersecurity experts, coordinated with law enforcement, and offered credit monitoring.
- FEDERALSEC 8-Kas victim2023-09-13
MGM Resorts International filed an 8-K on September 13, 2023, reporting a cybersecurity issue disclosed via press release on September 12, 2023. The filing provides no details on the nature of the incident, data types affected, or number of individuals impacted.
- 🦬Montana State AGas victim2019-09-05
MGM Resorts International reported a data breach to the Montana Attorney General. The breach was reported on 2019-09-05. The breach occurred from 7/7/2019 to 7/24/2019. 19 Montana residents were affected.
Subsidiary disclosures (1)filed by group companies
◈ These filings were made by or about subsidiaries of MGM RESORTS INTERNATIONAL — not by MGM RESORTS INTERNATIONAL itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.