Skip to content

MGM Resorts cyberattack sparked customer data breach, cost the company $100 million

Oct. 06, 2023
5 min read
(Photo by Ryan Smith/The Points Guy)
The cards we feature here are from partners who compensate us when you are approved through our site, and this may impact how or where these products appear. We don’t cover all available credit cards, but our analysis, reviews, and opinions are entirely from our editorial team. Terms apply to the offers listed on this page. Please view our advertising policy and product review methodology for more information.

Regulatory filings and a letter from MGM Resorts CEO William Hornbuckle Wednesday claim a recent cyberattack entailed both a leak of customer data as well as a hefty financial hit to the company.

Hornbuckle attempted to downplay just how severe the data break was, however.

"We have determined that because of our fast, early response, the incident did not result in a compromise of any customer bank account numbers or payment card information," Hornbuckle said in a public letter. "We do understand that the criminal actors obtained certain personal information belonging to some customers who transacted with us prior to March 2019."

Hackers obtained data like customer names, contact information, date of birth, gender and driver's license numbers. A "more limited number" of Social Security numbers and passport numbers were also hacked during the attack, Hornbuckle wrote.

"We have no evidence that the criminal actors have used this data to commit identity theft or account fraud," he added.

Hornbuckle noted the company shut down IT systems to mitigate the risk of any widespread data leak and worked with federal law enforcement and external cybersecurity experts on investigating the attack.

The company did not pay off hackers demanding a ransom like Caesars Entertainment did weeks prior to the MGM cybersecurity issue, the Wall Street Journal reported this week.

While the Federal Bureau of Investigation discourages companies from paying cyber hackers a ransom, Caesars is believed to have paid roughly $15 million in ransom. The company claims its operations weren't impacted, per earlier WSJ reporting.

But Caesars did note in a September regulatory filing that hackers "acquired a copy of, among other data, our loyalty program database, which includes driver's license numbers and/or social security numbers for a significant number of members in the database."

Daily Newsletter
Reward your inbox with the TPG Daily newsletter
Join over 700,000 readers for breaking news, in-depth guides and exclusive deals from TPG’s experts

The Caesars filing last month emphasized there was "no evidence to date that any member passwords/PINs, bank account information, or payment card information (PCI) were acquired by the unauthorized actor."

MGM's fallout

Social media reports in recent weeks depicted a state of bedlam at MGM Resorts, ranging from shutdown slot machines to manual credit card processing, following the cyberattack.

The CEO's letter Wednesday claims "the vast majority of our systems have been restored."

But a filing with the U.S. Securities and Exchange Commission indicates the attack likely caused the company to take a $100 million hit. The MGM Resorts filing attributes much of this to guests changing or canceling reservations during the month of September, which had an 88% occupancy rate across the company this year compared to 93% in 2022.

The company expects occupancy rates across its resorts to be 93% in October, slightly down from the 94% seen the same month last year, but then fully recover in November.

The SEC filing reiterated the company believed the "unauthorized third-party activity" is now contained.

What to do if your personal information was stolen at MGM or Caesars

Hornbuckle indicated customers whose data was comprised in the cyberattack will have been notified via email. MGM Resorts is offering free credit monitoring and free identity protection services to those impacted.

The company also established a dedicated call center at 1-800-621-9437 that can be reached Monday through Friday from 9 a.m. until 11 p.m. EST and from 11 a.m. until 8 p.m. on Saturdays and Sundays. Those who dial in should reference number B105892 when calling.

There is also a dedicated website outlining additional information of the cyberattack and steps to take to protect personal information, including remaining alert for unsolicited communications involving personal information and monitoring credit reports for potential fraud.

While Caesars claims its operations were back to normal, the company still indicated it would notify customers "in the coming weeks" impacted by its own data breach.

If you aren't sure if you were impacted, you can reach out to a dedicated response line for Caesars at 1-888-652-1580 from 9:00 a.m. to 9:00 p.m. EST, Monday through Friday other than on holidays.

What about Marriott?

The timing of the MGM Resorts cyberattack arrived weeks ahead of the planned launch month of a new partnership between the casino conglomerate and Marriott International.

The new deal, replacing a prior partnership between MGM and Hyatt, was expected to be a deeper relationship involving a new collection brand as well as tie-ins to the BetMGM online betting and gaming platform.

It is unclear if the cyberattack pushed back the planned October launch of the MGM Collection with Marriott Bonvoy. Representatives with Marriott did not respond to TPG's request for comment in time for publication.

But it certainly appears MGM is ready to at least be back to normal in November in time for the Formula 1 Las Vegas Grand Prix.

"The Company believes it is well-positioned to have a strong fourth quarter, with record results expected in November primarily driven by Formula 1," reads the MGM Resorts SEC filing from Wednesday.

Related reading:

Featured image by RYAN SMITH/THE POINTS GUY
Editorial disclaimer: Opinions expressed here are the author’s alone, not those of any bank, credit card issuer, airline or hotel chain, and have not been reviewed, approved or otherwise endorsed by any of these entities.

TPG featured card

Rewards rate
4XEarn 4X Membership Rewards® points per dollar spent on purchases at restaurants worldwide, on up to $50,000 in purchases per calendar year, then 1X points for the rest of the year.
4XEarn 4X Membership Rewards® points per dollar spent at US supermarkets, on up to $25,000 in purchases per calendar year, then 1X points for the rest of the year.
5XNew! Earn 5X Membership Rewards® points on prepaid hotel stays booked through AmexTravel.com or the Amex Travel App.
3XEarn 3X Membership Rewards® points on flights booked through AmexTravel.com, the Amex Travel App, or purchased directly from airlines.
2XEarn 2X Membership Rewards® points on prepaid car rentals booked through AmexTravel.com or the Amex Travel App and cruises booked and paid through AmexTravel.com.
1XEarn 1X Membership Rewards® point per dollar spent on all other eligible purchases.
Intro offer
Open Intro bonus
As High As 100,000 points. Find Out Your Offer.
Annual fee
$325
Regular APR
See Pay Over Time APR
Recommended credit
Open Credit score description
Excellent to Good

Pros

  • Valuable dining and food-related credits
  • Flexible rewards with airline and hotel transfer partners
  • Multiple travel and purchase protections
  • No foreign transaction fees
  • Access to Amex Offers for additional savings (enrollment required)

Cons

  • Not as useful for those living outside the U.S.
  • Some may have trouble using Uber and other dining credits
  • You may be eligible for as high as 100,000 Membership Rewards® Points after you spend $8,000 in eligible purchases on your new Card in your first 6 months of Card Membership. Welcome offers vary and you may not be eligible for an offer. Apply to know if you’re approved and find out your exact welcome offer amount – all with no credit score impact. If you’re approved and choose to accept the Card, your score may be impacted.
  • Earn 4X Membership Rewards® points per dollar spent on purchases at restaurants worldwide, on up to $50,000 in purchases per calendar year, then 1X points for the rest of the year.
  • Earn 4X Membership Rewards® points per dollar spent at US supermarkets, on up to $25,000 in purchases per calendar year, then 1X points for the rest of the year.
  • New! Earn 5X Membership Rewards® points on prepaid hotel stays booked through AmexTravel.com or the Amex Travel App.
  • Earn 3X Membership Rewards® points on flights booked through AmexTravel.com, the Amex Travel App, or purchased directly from airlines.
  • Earn 2X Membership Rewards® points on prepaid car rentals booked through AmexTravel.com or the Amex Travel App and cruises booked and paid through AmexTravel.com.
  • Earn 1X Membership Rewards® point per dollar spent on all other eligible purchases.
  • Pay It® lets you tap in the American Express® App to quickly pay for small purchase amounts throughout the month and still earn rewards the way you usually do. Plan It® gives you the option to split up big purchases into equal monthly payments with a fixed fee. You’ll know upfront exactly how much you’ll pay.
  • Updated! $120 Dining Credit: Earn up to a total of $10 in statement credits monthly when you pay with the Gold Card at Grubhub (including Seamless), Buffalo Wild Wings, Five Guys, The Cheesecake Factory, and Wonder. This can be an annual savings of up to $120. Enrollment required.
  • $100 Resy Credit: Get up to $100 in statement credits each calendar year at over 10,000 qualifying U.S. Resy restaurants after you pay for eligible purchases with the American Express® Gold Card. That’s up to $50 in statement credits semi-annually. Enrollment required.
  • $84 Dunkin' Credit: Earn up to $7 in monthly statement credits after you pay with the American Express® Gold Card at U.S. Dunkin’ locations. Enrollment required.
  • $120 Uber Cash on Gold: Enjoy up to $120 in Uber Cash annually with your Gold Card. Just add your Card to your Uber account and you'll get $10 in Uber Cash each month to use on orders and rides in the U.S. when you select an Amex Card for your transaction.
  • New! As an American Express® Gold Card Member, you can enjoy complimentary Hertz Five Star® Status. Enjoy benefits like skipping the counter at select locations, adding an additional driver at no additional cost*, and vehicle upgrades**. Benefit enrollment and Hertz Gold+ registration are required. *Additional drivers must meet standard rental qualifications and must be a spouse or domestic partner to qualify as complimentary. Other additional drivers subject to fees. **Benefits are subject to availability and vary by location. Additional Hertz program Terms and Conditions including age restrictions apply.
  • Take advantage of a $100 credit towards eligible charges* at over 1,300 upscale hotels worldwide when you book The Hotel Collection through AmexTravel.com or the Amex Travel App **. *Eligible charges vary by property. **The Hotel Collection requires a two-night minimum stay.
  • Book your travel through the Amex Travel App with added peace of mind – backed by American Express® service and support. Only for American Express® Card Members.
  • Whenever you need us, we're here. Our Member Services team will ensure you are taken care of. From lost Card replacement to statement questions, we are available to help 24/7.
  • No Foreign Transaction Fees.
  • Annual Fee is $325.
  • Terms Apply.