Breach report
Travel & HospitalityMGM Resorts
Details of 10 million MGM hotel guests leaked online
Personal details of more than 10.6 million former MGM Resorts hotel guests, including celebrities and government officials, surfaced on a hacking forum in February 2020, months after the casino operator quietly handled a 2019 cloud server breach.
Reported by TechRadar
Records exposed
10.7M
About 10.6 million hotel guests
Scale vs. largest on file
- When
- 2019 (disclosed 2020)
- How they got in
- Unauthorized access to a cloud server
- Sector
- Travel & Hospitality
In February 2020, technology news site ZDNet reported that a file containing personal information on 10,683,188 former guests of MGM Resorts hotels had been posted on a hacking forum. MGM confirmed that the data came from an incident discovered in the summer of 2019, when it found unauthorized access to a cloud server holding information about previous guests. The company said it had notified affected guests at the time, though some people identified in the leak said they had never received notice.
Most of the exposed records contained what MGM described as phonebook-style information: names, home addresses, phone numbers, email addresses and dates of birth. For roughly 1,300 guests, passport numbers, driver's license numbers or military ID numbers were also included. MGM said no financial data, payment card information or passwords were involved. Some of the records dated back several years, reflecting guests who had not stayed with the company since around 2017.
The dataset drew attention because of who was in it. Researchers who examined the files found entries for celebrities and business leaders, including Twitter chief executive Jack Dorsey and singer Justin Bieber, as well as journalists, employees of major technology companies and staff from U.S. government agencies such as the Department of Homeland Security and the Secret Service. Security experts warned that the information could be used for targeted phishing, SIM-swap attempts and social engineering long after the original intrusion.
The scale of the leak appeared to grow later in 2020, when a hacker advertised what was claimed to be data on more than 142 million MGM guests; researchers believed it largely overlapped with the earlier leak and contained duplicates. MGM faced class action lawsuits over the 2019 breach. Those claims were eventually consolidated with litigation over a separate and far more disruptive 2023 ransomware attack on MGM by the Scattered Spider group, and in 2025 the company agreed to a combined $45 million settlement covering both incidents.
The MGM case showed how data from a breach considered contained can resurface years later and cause new harm. It also illustrated the value to criminals of hospitality records, which link names to home addresses, phone numbers and travel habits. For companies, the lesson was to secure cloud storage properly and to notify every affected customer clearly; for guests, it was a reminder that old accounts and stays can leave a lasting data trail.