MGM's 2019 data breach may have affected 142M+ guests, not 10.6M as first reported, according to dark web marketplace; data includes contact details and DoB
EXCLUSIVE: The MGM Resorts 2019 data breach is much larger than initially reported. — The MGM Resorts 2019 data breach …
Context & Ripple Effects
In February 2020, a hacking forum posted home addresses and other personal data for what was then believed to be 10.6M+ MGM Resorts guests who stayed before 2018. A dark web marketplace now claims the true scope is more than 142 million guests, with contact details and dates of birth included — a revision that would make this one of the larger hospitality data exposures on record.
The claim lands while MGM is still absorbing the financial tail of the same incident: the company later agreed to pay $45M to settle 14 class actions tied to the 2019 breach and its 2023 ransomware attack (the $45M settlement). Hospitality has form here — Marriott's own breach estimate moved repeatedly after disclosure, from an initial 500M down to 383M stolen records, so revised counts have precedent in the sector.
First-order effects
- Guests whose contact details and dates of birth were exposed face heightened phishing and identity-fraud risk, and the expanded figure widens the pool of potential class members beyond the 10.6M originally notified.
- For MGM, a 142M+ confirmed scale would strengthen plaintiffs' leverage in ongoing litigation and regulatory scrutiny that already produced the $45M settlement covering both the 2019 breach and the 2023 ransomware attack.
Second-order effects
- Rivals including Caesars — which paid hackers tens of millions after a 2023 breach threatened data release (Caesars' reported payout) — and Marriott, which disclosed a separate 5.2M-guest breach in April 2020, face renewed pressure to audit and re-disclose their own guest-data inventories.
- Dark web marketplaces emerge as an alternative disclosure channel that can force revisions companies did not make themselves, shifting negotiating power in breach disputes toward whoever holds and resells the data.
Third-order effects
- If breach sizes keep getting revised upward months or years after first disclosure, regulators and courts may treat initial company-reported counts as floor estimates rather than authoritative figures, changing how settlement values are calculated.
- Hotels' loyalty-program databases — rich in identity attributes but lightly monitored — look increasingly like the sector's core systemic liability, pushing hospitality toward treating guest-data minimization as a security control rather than a marketing asset.
The trend: Hospitality breach disclosures are converging on a pattern where third-party data brokers and forums reveal scale long after the company's first count, turning guest databases into the industry's most contested liability.