Skip to content
Breach Spot
  • The Breach News
  • Check your exposure
REPORT BREACH
Breach SpotBreach Spot
  • The Breach News
  • Check your exposure
REPORT BREACH
Breach SpotBreach Spot

MGM Resorts International Settlement: Discover Your Eligibility for a Share of the $45 Million Payout

  • adminadmin
  • March 9, 2025
  • data-breaches

MGM Resorts International has recently disclosed two significant data breaches, one occurring in July 2019 and another in September 2023. The resort company has reached a settlement agreement, allocating a substantial compensation fund of $45 million for those impacted by these breaches.

The data leaks involved extensive exposure of sensitive personal information belonging to customers and guests. Among the compromised data were vital identifiers such as names, addresses, telephone numbers, email addresses, dates of birth, driver’s license numbers, passport numbers, Social Security numbers, and military identification numbers. These breaches represent a severe lapse in data security, with significant ramifications for the individuals affected.

In response to the rising threat of cyberattacks, MGM Resorts implemented a proactive measure in September, executing a ten-day shutdown of their computer systems. This action was taken to protect against potential data breaches, highlighting the increasing necessity for heightened security protocols in the face of evolving cyber threats.

MGM Resorts operates a wide array of hotel properties across the United States, significantly in Las Vegas. Their portfolio includes iconic establishments such as the Bellagio, ARIA, and MGM Grand, among others, as well as locations in other states including MGM Springfield and Borgata in New Jersey. The diverse geographical spread of these properties amplifies the potential impact of data breaches on a broad consumer base.

For individuals in the United States who have had their private information compromised and received notification, the settlement provides a framework for filing claims. These individuals will receive unique identifiers enabling them to submit claims for restitution. Furthermore, any financial losses linked to the breaches, amounting to as much as $15,000, are also compensable. Claimants are instructed to provide supporting documentation, which may include receipts or bank statements, to substantiate their losses. Certain class members may also qualify for a flat cash payment without the need for extensive documentation.

In addition to these payments, all individuals who file claims will be entitled to one year of financial account monitoring, a necessary measure to help mitigate the risk of identity theft following such a breach. The tiered compensation structure offers varying amounts based on the nature of the compromised information, further emphasizing the serious implications of the data exposure.

This incident underscores the evolving landscape of cybersecurity threats facing organizations today. The tactics employed by potential adversaries in these breaches could align with several categories within the MITRE ATT&CK framework. These may include initial access strategies through phishing or exploitation of vulnerabilities, as well as persistence techniques that embed malicious entities within an organization’s systems. The necessity for robust cybersecurity measures and vigilant monitoring is paramount for organizations to protect their sensitive data and maintain consumer trust in an increasingly digital world.

The deadline for affected individuals to file claims through the dedicated online portal is set for June 3, while those wishing to opt out of the settlement or contest it may do so until May 19, 2025. The implications of these breaches and the subsequent settlement highlight the critical need for operational vigilance among business leaders as they navigate the complex realm of cybersecurity.

Source link

Help Prevent Exploitation, Report Breaches

Help to prevent further data unauthorized access or potential exploitation. Protect others by sharing vital breach information. If you’ve discovered a new data breach

REPORT HERE
Trending now

"Fortinet" AI Android Apple artificial intelligence Artificial Intelligence & Machine Learning AT&T AWS CISA Cisco Cloudflare cloud security compliance CrowdStrike cryptocurrency Cybercrime cybersecurity data breach data breaches data privacy data security encryption ESET Facebook FBI Fraud Management GitHub Google healthcare HIPAA Kaspersky machine learning Malware Mandiant Meta Microsoft Multi-Factor Authentication OpenAI Palo Alto Networks phishing ransomware Salesforce Telegram Trend Micro Windows

Sector alert bulletin

Subscribe to your sector-specific insight newsletter to stay updated on potential data breaches and ongoing cyber-attacks targeting your industry

Stay informed and prepared against emerging security threats.

SUSCRIBE NOW

Related Posts

🔍 Weekly Roundup: iPhone Spyware, Microsoft 0-Day Vulnerability, TokenBreak Breach, AI Data Leaks, and More!

  • April 30, 2026

⚡ Weekly Cybersecurity Update: BadCam Attack, WinRAR Exploits, EDR Threats, NVIDIA Vulnerabilities, Ransomware Incidents & More

Published: Aug 11, 2025

This week has highlighted the rapid pace of cyber threats, urging businesses to remain vigilant. Attackers are uncovering vulnerabilities in widely-used software and utilizing innovative tactics to bypass security measures. Even a single unpatched vulnerability can create pathways for data breaches or unauthorized system access. Time is of the essence—failure to regularly update defenses can result in severe consequences. The imperative is clear: proactive measures are essential to safeguard your business.

Here’s a summary of the most significant cybersecurity developments this week, including recent flaws in WinRAR and NVIDIA Triton, along with essential advanced attack strategies to be aware of. Let’s dive into the details.

⚡ Threat of the Week
Trend Micro Issues Warning on Actively Exploited 0-Day — Trend Micro has provided temporary mitigations to tackle serious security vulnerabilities in on-premise versions of Apex One Management Console, which are reportedly being exploited in the wild. The flaws include CVE-2025-54948 and CVE-2025-54987.

  • April 30, 2026

Cybercrime Groups ShinyHunters and Scattered Spider Unite for Targeted Extortion Campaign Against Businesses

August 12, 2025
Cybercrime / Financial Security

A continuing data extortion initiative targeting Salesforce clients may soon expand its focus to encompass financial services and tech providers, as recent findings suggest collaboration between ShinyHunters and Scattered Spider. “This latest series of attacks attributed to ShinyHunters indicates a significant tactical shift, moving past their prior methods of credential theft and database exploitation,” reports ReliaQuest to The Hacker News. Their new approach incorporates strategies akin to those used by Scattered Spider, including highly-targeted vishing (voice phishing) and social engineering tactics, the use of applications that pose as legitimate tools, and Okta-themed phishing pages to deceive victims into revealing credentials during vishing attempts, alongside VPN obfuscation for data exfiltration. ShinyHunters, which first emerged in 2020, is a financially motivated group that has executed numerous data breaches targeting major corporations.

  • April 30, 2026

Charon Ransomware Targets Middle East Industries with Advanced Evasion Techniques

Aug 13, 2025
Endpoint Security / Cybercrime

Cybersecurity researchers have unveiled a new campaign featuring an undocumented ransomware variant named Charon, targeting the public sector and aviation industry in the Middle East. According to Trend Micro, the attackers employed tactics reminiscent of advanced persistent threat (APT) groups, including DLL side-loading and process injection, successfully evading endpoint detection and response (EDR) systems. The use of DLL side-loading parallels techniques associated with the China-linked hacking group Earth Baxia, which has previously targeted government entities in Taiwan and the Asia-Pacific region to deploy a backdoor known as EAGLEDOOR, following the exploitation of a now-patched vulnerability in OSGeo GeoServer GeoTools. “The attack chain utilized a legitimate browser-related file, Edge.exe (originally cookie_exporter.exe), to sideload a…”

  • April 29, 2026

Real-time data breach monitoring by scanning public databases, criminal forums, and online markets to detect exposed credentials and sensitive data.

Industries
  • Enterprise Security Teams
  • Financial Services
  • Retail and E-commerce
  • Legal Services
  • Law Enforcement
Commonly Used For
  • Penetration Testing
  • M&A Risk Research
  • Vulnerability Assessment
  • Red Team Operation
  • Enterprise Security
Contact Us

Need help or have a question?

Email: info@breachspot.com
Phone: +1 (914) 2943243

Copyright © 2026 - Breachspot, Security Breaches Spotted