DataBreachCaseFile.com
Investigation OpenMassachusetts AG filing · March 7, 2026

MGM Resorts International Reports Data Security Incident in Massachusetts

MGM Resorts International has formally reported a data security incident to Massachusetts authorities on March 7, 2026. This incident involves an unauthorized compromise of the company's network infrastructure and data systems. The filing indicates that personal information may have been affected, and investigations are ongoing.

State
Massachusetts
Reported
March 7, 2026

MGM Resorts International, a global hospitality and entertainment conglomerate, submitted a data security incident report to the Massachusetts Attorney General on March 7, 2026. This official filing acknowledges an unauthorized compromise within its network and data systems.

As a large enterprise, MGM Resorts International manages extensive personal information belonging to its guests and employees. This data is used for various operational aspects, including reservations, loyalty programs, and financial transactions. While the specific types of information involved in this incident are not detailed in the public record and are part of an ongoing investigation, the company has indicated that personal information may have been exposed.

Data breaches affecting major hospitality and entertainment groups often stem from sophisticated cyberattacks targeting core administrative environments or guest databases. Such incidents typically aim to exfiltrate significant volumes of data. The full scope and technical specifics of this particular compromise are currently under investigation by MGM Resorts International.

When personal information is compromised in a security incident, individuals face potential risks, including targeted phishing attempts and the unauthorized use of their details. It is important for anyone who receives a direct notification from MGM Resorts International regarding this incident to understand these potential implications.

Individuals who believe they may be affected should take general precautions. These include regularly monitoring their financial accounts and credit reports for any unusual or suspicious activity. Placing fraud alerts with credit bureaus is another widely recommended step to help protect against potential misuse of personal information. Additionally, maintaining vigilance regarding unsolicited communications, such as emails or phone calls requesting personal details, is advisable.

More Massachusetts data breach cases