Data breaches have become a defining risk of modern digital life. The Mgm Resorts breach is one of the most significant in recent memory — and if you've ever had an account with the affected service, your personal data may be circulating among cybercriminals right now.
This guide explains exactly what happened, what data was taken, and how you can check whether your information was exposed — for free, in 30 seconds.
What Happened?
The details of this breach are covered in the FAQ section below, where we answer the most important questions clearly and concisely. The key facts: who was affected, what data was taken, how attackers got in, and what the consequences have been.
Why Does This Still Matter?
Many people assume that because a breach happened years ago, the risk has passed. In reality, stolen data is sold, traded, and reused for years after a breach. Credentials from old breaches are used in credential stuffing attacks — automated attempts to log in to your other accounts using the same email and password combination.
If you reused the same password across multiple sites, one old breach can unlock dozens of your current accounts.
How to Check If You Were Affected
The fastest way is to use our free breach checker. Enter your email address and we'll scan it against known breach databases instantly — no signup required.
If your email appears in a breach, you'll see exactly which breaches affected it and what type of data was exposed. That tells you precisely where to start.
What to Do If You Were Affected
If your data was in this breach — or any breach — take these steps:
- Change the affected password immediately — especially if you reused it anywhere else.
- Enable two-factor authentication on every account that supports it, starting with email and banking.
- Check for suspicious activity on financial accounts if payment data was involved.
- Be alert for phishing — attackers use breach data to craft convincing personalised scam messages.
- Freeze your credit if your Social Security number, passport, or government ID was exposed.
Frequently Asked Questions
When did the MGM Resorts data breach happen?
The attack began on 10 September 2023 after attackers used a vishing (voice phishing) call to impersonate an MGM employee to IT support and gain access credentials. The ransomware attack disrupted MGM operations for approximately 10 days.
How did attackers breach MGM Resorts?
ALPHV/BlackCat ransomware group, working with the Scattered Spider hacking collective, used social engineering. Attackers found an MGM employee on LinkedIn, called MGM's IT help desk impersonating that employee, and obtained access credentials through the call — bypassing technical security entirely.
What data was stolen in the MGM breach?
Personal data for over 30 million past MGM hotel guests was exposed, including names, contact information, dates of birth, driver's licence numbers, Social Security numbers, and passport numbers. Some guests' financial information was also taken.
What was the impact of the MGM ransomware attack?
MGM suffered estimated losses exceeding $100 million. Slot machines went offline, hotel check-in systems failed, ATMs stopped working, and casino operations across multiple MGM properties were severely disrupted for days.
How do I check if my MGM data was exposed?
Enter your email address in the free checker at Scan My Shadow. MGM sent breach notifications to affected customers. If you stayed at an MGM property and provided ID, assume your details may be in the stolen data.
Sources
- MGM Resorts – 8-K SEC filing on cybersecurity incident
- CISA – Scattered Spider advisory
- Have I Been Pwned – MGM breach entry