Skip to main content
Breach Signal

Breach report

Travel & Hospitality

MGM Resorts

Details of 10 million MGM hotel guests leaked online

Personal details of more than 10.6 million former MGM Resorts hotel guests, including celebrities and government officials, surfaced on a hacking forum in February 2020, months after the casino operator quietly handled a 2019 cloud server breach.

Reported by TechRadar

Records exposed

10.7M

About 10.6 million hotel guests

Scale vs. largest on file

When
2019 (disclosed 2020)
How they got in
Unauthorized access to a cloud server
Sector
Travel & Hospitality

In February 2020, technology news site ZDNet reported that a file containing personal information on 10,683,188 former guests of MGM Resorts hotels had been posted on a hacking forum. MGM confirmed that the data came from an incident discovered in the summer of 2019, when it found unauthorized access to a cloud server holding information about previous guests. The company said it had notified affected guests at the time, though some people identified in the leak said they had never received notice.

Most of the exposed records contained what MGM described as phonebook-style information: names, home addresses, phone numbers, email addresses and dates of birth. For roughly 1,300 guests, passport numbers, driver's license numbers or military ID numbers were also included. MGM said no financial data, payment card information or passwords were involved. Some of the records dated back several years, reflecting guests who had not stayed with the company since around 2017.

The dataset drew attention because of who was in it. Researchers who examined the files found entries for celebrities and business leaders, including Twitter chief executive Jack Dorsey and singer Justin Bieber, as well as journalists, employees of major technology companies and staff from U.S. government agencies such as the Department of Homeland Security and the Secret Service. Security experts warned that the information could be used for targeted phishing, SIM-swap attempts and social engineering long after the original intrusion.

The scale of the leak appeared to grow later in 2020, when a hacker advertised what was claimed to be data on more than 142 million MGM guests; researchers believed it largely overlapped with the earlier leak and contained duplicates. MGM faced class action lawsuits over the 2019 breach. Those claims were eventually consolidated with litigation over a separate and far more disruptive 2023 ransomware attack on MGM by the Scattered Spider group, and in 2025 the company agreed to a combined $45 million settlement covering both incidents.

The MGM case showed how data from a breach considered contained can resurface years later and cause new harm. It also illustrated the value to criminals of hospitality records, which link names to home addresses, phone numbers and travel habits. For companies, the lesson was to secure cloud storage properly and to notify every affected customer clearly; for guests, it was a reminder that old accounts and stays can leave a lasting data trail.

More from the wire

More in Travel & Hospitality.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.