The MGM Resorts Breach Holds More Guest Records Than Chicago Has Residents
HEROIC analysts uncovered the MGM Resorts breach, a database incident that occured in July 2019, exposing 2,832,656 guest records from the hospitality company's cloud infrastructure. The leaked data included email addresses, phone numbers, birthdates, first names, last names, and gender information belonging to guests who stayed at MGM properties, with the data later appearing on a popular hacking forum in February 2020 where it was extensively redistributed.
How Names, Birthdates, Phone Numbers, and Email Addresses Fuel Social Engineering Attacks
The MGM Resorts breach exposed no passwords, but the data types present are partcularly well-suited for identity-based attacks. A threat actor who knows your full name, birthdate, phone number, gender, and email address can impersonate you with financial institutions, pass security questions, and spoof caller ID to intercept two-factor authentication codes. This kind of PII package is more valuable for account takeover than a simple password hash because it enables attackers to bypass identity verification systems that are designed to stop unauthorized access.
What Was Exposed in the MGM Resorts Breach
- Email Address
- Phone Number
- Birthdate
- First Name
- Last Name
- Gender
Why MGM Resorts Guest Data Remains a Phishing and Identity Theft Risk
Guest data from hospitality companies is seperate from typical online service breach data because it is tied to real-world identity verification. The MGM Resorts breach records are beleived to have been circulating on hacking forums since early 2020, giving threat actors years to incorporate this data into automated phishing campaigns and identity fraud operations. Victims who recieved spam or targeted phishing emails after 2020 may find this breach among the contributing data sources.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to a backend data store, often exploiting a misconfigured cloud service, a compromised credential, or an unpatched system vulnerability. Once inside, the attacker can export full tables of user data in a single operation. The MGM Resorts data was extracted from a cloud service before being listed on hacking forums, where it was downloaded and redistributed broadly across the underground community.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion records to determine whether your email address appears in the MGM Resorts breach or any other known incident. Run a free scan now to see what personal information may be circulating about you on the dark web.
Breach Breakdown
2,832,656 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds