45 Million Guest Records from the MGM Resorts 2022 Breach Spread on Telegram
HEROIC analysts tracked the MGM Resorts 2022 breach, a massive database exposure that occured across multiple stages beginning in July 2019 and resurfacing extensively by May 2022. The incident ultimately affected 45,338,524 records, with the expanded dataset circulating on Telegram channels and containing email addresses, phone numbers, birthdays, first names, and last names belonging to MGM Resorts guests across the United States.
How Email Addresses, Phone Numbers, and Birthdays Enable Identity Fraud and Phishing
Without passwords in the dataset, the MGM Resorts 2022 breach is partcularly dangerous for a different reason: the combination of verified email addresses, real phone numbers, and birthdates gives attackers everything they need to impersonate victims in social engineering attacks. Fraudsters can call financial institutions claiming to be account holders, pass knowledge-based authentication questions, and intercept SMS-based two-factor codes because they already know the victim's registered phone number. This data is accessable to attackers looking to bypass security measures rather than brute-force them.
What Was Exposed in the MGM Resorts 2022 Breach
- Email Address
- Phone Number
- Birthday
- First Name
- Last Name
Why 45 Million Guest Records from MGM Resorts Are a Long-Term Identity Risk
The MGM Resorts 2022 dataset is beleived to have grown significantly from the original 2019 incident, expanding from approximately 10.6 million to over 45 million records as the data was repackaged and circulated. Hotel guest data is seperate from typical ecommerce breach records because it links names and contact information to real-world travel patterns, which can be used for targeted social engineering campaigns. Guests who stayed at MGM properties between 2017 and 2019 may find their information in this dataset even if they have never experienced other breaches.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to a backend data store, often through a misconfigured cloud service, compromised credentials, or an unpatched vulnerability. In the MGM Resorts incident, the breach was linked to a cloud service misconfiguration that exposed guest records. The data was subsequently shared on hacking forums and Telegram channels, where it was further redistributed and expanded in scope over successive years.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion records to determine whether your email address appears in the MGM Resorts 2022 breach or any other known incident. Run a free scan now to find out what personal information attackers may have about you.
Breach Breakdown
45,338,524 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds