Home addresses and other data of 10.6M+ guests who stayed at MGM Resorts hotels before 2018, including Jack Dorsey, were posted on a hacking forum this week
MGM Resorts said security incident took place last summer and notified impacted guests last year.
Context & Ripple Effects
This is an old breach resurfacing: MGM says the incident happened in summer 2019 and that it already notified affected guests, but the actual guest records — home addresses and contact details for 10.6M+ pre-2018 visitors, including Block CEO Jack Dorsey — only became publicly visible this week when they were dumped on a hacking forum. The disclosure gap between notification and exposure is what makes the story land now.
The scale question was still open at the time: months later, a dark web marketplace indicated the same 2019 breach may have touched 142M+ guests, not 10.6M. The episode also fits a hotel-sector pattern — Marriott disclosed its own breach affecting 5.2M guests weeks after this dump — and MGM would remain a target, suffering a far more disruptive cyberattack in September 2023 attributed to Scattered Spider.
First-order effects
- Guests in the dump, from ordinary travelers to named executives like Dorsey, gain a live risk of targeted phishing and social engineering built on verified home addresses — precisely the attack vector Scattered Spider later used against MGM itself via help-desk calls.
- MGM's 'already notified' defense weakens: the public forum posting reopens reputational exposure for a 2019 incident the company had considered closed.
Second-order effects
- Hotel peers face the same loyalty-database liability — Marriott's separate 5.2M-guest disclosure shows guest PII is a sector-wide attack surface, forcing rivals to treat reservation systems as breach assets rather than marketing infrastructure.
- Dark web marketplaces gain a pricing benchmark for aged hospitality data, incentivizing brokers to hold and resell older breach corpora rather than discard them.
Third-order effects
- If the pattern holds — a 2019 breach whose scope kept growing, followed by MGM's 2023 operational shutdown — hospitality becomes a repeat-victim category where regulators and insurers price guest-data risk as chronic, not episodic, pushing chains toward consolidated identity controls across properties.
The trend: Hotel guest databases are becoming long-tail breach assets that resurface on forums years after the original incident, with each re-exposure compounding the operator's security debt.