Clustered 12 filings across 9 jurisdictions · filing window Oct 5, 2023 → Dec 5, 2023. View entity profile → Other incidents for this victim →
incident inc_3b7cc1809a734581 · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Discovery to SEC materiality determination
Materiality determination to SEC 8-K filing
Time between earliest and latest filing
Not recorded for this incident
Leak precedence — no leak-site claim in this cluster.
CA DE FEDERAL ME MT OR SC VT
SEC 8-K · State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
12 filings across 9 jurisdictions · Oct 5, 2023 – Dec 5, 2023 · 3 milestones
Sep 8, 2023 → Sep 12, 2023
When the intrusion reportedly occurred, per the linked filings
Sep 8, 2023 – Sep 29, 2023
Earliest reported discovery Sep 8, 2023
Sep 8, 2023
Reported by WASHINGTON AG, OREGON AG, MAINE AG filings
Sep 9, 2023
Reported by SOUTH CAROLINA AG filing
Sep 12, 2023
Reported by SEC 8-K filing
Oct 5, 2023
Registrant determined the incident material — starts the SEC 4-business-day clock
MGM Resorts International disclosed a cybersecurity incident identified on September 12, 2023. Criminal actors accessed customer data including names, contact info, driver's license numbers, and for some, SSNs and passports. Data dates back to March 2019. The incident was contained, systems restored, and free credit monitoring offered. Estimated financial impact is ~$100M in Q3 2023 EBITDAR.
MGM Resorts International disclosed that an unauthorized third party obtained personal information of some customers on September 11, 2023. The breach window is listed as September 8-12, 2023. Affected data includes names, contact info, gender, date of birth, and driver's license numbers; for a limited number of customers, Social Security and passport numbers were also affected. Passwords, bank accounts, and payment card information were not affected. MGM shut down systems, engaged cybersecurity experts, and is offering credit monitoring.
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Sep 29, 2023
Reported by DELAWARE AG filing
MGM Resorts International, a business sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2023-09-08 and filed notice on 2023-10-05. 811,740 Washington residents were affected. 27 days elapsed between awareness and notification. 0 days to identify the breach. 4 days to contain the breach.
Affected (this filing): 811,740
MGM Resorts International reported a data breach to the Oregon Attorney General. The breach was reported on 2023-10-05. The breach occurred during 9/8/2023 - 9/12/2023. The breach was discovered on 9/8/2023. 0 individuals were affected. Notice was sent on 10/5/2023.
Affected (this filing): 0
MGM Resorts International notified consumers of a data breach involving unauthorized access to systems. The incident compromised personal information including names, Social Security numbers, and dates of birth. MGM engaged cybersecurity experts, coordinated with law enforcement, and provided two years of complimentary credit monitoring and identity protection services through Experian to affected individuals.
MGM Resorts International issued a state-AG breach notification to residents of multiple jurisdictions (including Delaware, Iowa, Maryland, Massachusetts, New Mexico, Oregon, Rhode Island, and D.C.). The company shut down systems, engaged cybersecurity experts, and coordinated with law enforcement. Affected individuals were offered 24 months of complimentary credit monitoring and identity protection through Experian. The notification references identity theft and fraud but does not specify the exact data types or number of affected individuals.
MGM Resorts International filed a notice regarding an external system breach (hacking) that occurred from September 8 to September 12, 2023, and was discovered on September 8, 2023. The breach compromised personal identifiers, including names and driver's license or non-driver identification card numbers. While the filing indicates zero Maine residents were affected, the company offered credit monitoring and identity protection services through Experian.
Affected (this filing): 0
MGM Resorts International notified Delaware and other state attorneys general of a cybersecurity incident involving unauthorized access to systems. The company shut down systems, engaged cybersecurity experts, and coordinated with law enforcement. Affected individuals were offered two years of complimentary credit monitoring and identity protection services through Experian. The incident involved personal information, including Social Security numbers.
MGM Resorts International disclosed a cybersecurity incident affecting customer systems. An unauthorized third party obtained personal information (names, contact info, DOB, driver's license, SSN, passport) starting September 11, 2023. MGM shut down systems, engaged cybersecurity experts, coordinated with law enforcement, and offered credit monitoring. Investigation was ongoing as of October 5, 2023.
MGM Resorts International reported a data breach to the Montana Attorney General. The breach was reported on 2023-10-05. The breach occurred on 9/11/2023. 1 Montana residents were affected.
Affected (this filing): 1
MGM Resorts International disclosed that an unauthorized third party obtained personal information of some customers on September 11, 2023. The breach window was identified as September 8-12, 2023. Affected data included names, contact information, gender, date of birth, Social Security numbers, and driver's license numbers. For a limited number of customers, passport numbers were also affected. Passwords, bank account numbers, and payment card information were not believed to be affected. MGM shut down certain systems, engaged cybersecurity experts, coordinated with law enforcement, and offered credit monitoring.
MGM Resorts International disclosed a September 2023 ransomware attack by the BlackCat group, affecting approximately 37 million individuals. The incident involved the encryption of data and exfiltration of customer PII, including names, addresses, and for some, SSNs and passport numbers. MGM engaged forensic investigators, notified law enforcement, and provided credit monitoring to affected individuals. The South Carolina Attorney General received a breach notice on October 5, 2023.
Affected (this filing): 37,000,000