MGM hotels hack sees 10.6 million customer accounts exposed

Names, address and passport details for the rich and famous found on a hacking forum, according to reports

The personal details of 10.6 million guests who stayed at MGM Resorts hotels have surfaced online after hackers accessed the chain's servers in July 2019. 

Names, addresses and passport details for guests up to 2017 were spotted on a hacking forum by Under the Breach, a soon-to-be-launched data breach monitoring platform that reported the find to ZDNet.  

MGM is the owner of a number of luxury in hotels in Las Vegas, and also elsewhere in the US, China and Japan. Its main Vegas hotel, the MGM Grand, is a popular destination for celebrities and often holds casino tournaments as well as the biggest boxing matches of the year - Tyson Fury will take on Deontay Wilder this weekend. 

The company confirmed it had been attacked in July 2019 and that it had notified affected customers a month later. The source of the leak is said to be a cloud server, which ZDNet suggested was misconfigured. IT Pro has contacted MGM for comment. 

"Last summer, we discovered unauthorised access to a cloud server that contained a limited amount of information for certain previous guests of MGM Resorts," the chain told ZDNet. "We are confident that no financial, payment card or password data was involved in this matter."

It is believed the personal information of high profile guests, such as Justin Bieber, Twitter founder Jack Dorsey and FBI agents have been found on the forum.

Related Resource

Your guide to managing cloud transformation risk

Realise the benefits. Mitigate the risks

Download now

While this is a large breach, it isn't as big as the one suffered by the Marriott chain of hotels which saw Chinese state actors access personal details and payment records for 500 million guests after it failed to properly patch a database for its Starwood brand of hotels. 

This is also the second report of hacking in Las Vegas this year after the city's security teams revealed they had thwarted a breach in January. 

Featured Resources

B2B under quarantine

Key B2C e-commerce features B2B need to adopt to survive

Download now

The top three IT pains of the new reality and how to solve them

Driving more resiliency with unified operations and service management

Download now

The five essentials from your endpoint security partner

Empower your MSP business to operate efficiently

Download now

How fashion retailers are redesigning their digital future

Fashion retail guide

Download now

Recommended

Most CISOs worry cloud software flaws aren’t being caught
cloud security

Most CISOs worry cloud software flaws aren’t being caught

7 Jun 2021

Most Popular

The benefits of workload optimisation
Sponsored

The benefits of workload optimisation

16 Jul 2021
Samsung Galaxy S21 5G review: A rose-tinted experience
Mobile Phones

Samsung Galaxy S21 5G review: A rose-tinted experience

14 Jul 2021
RMIT to be first Australian university to implement AWS supercomputing facility
high-performance computing (HPC)

RMIT to be first Australian university to implement AWS supercomputing facility

28 Jul 2021