MGM Resorts is paying $45 million to settle a class action lawsuit stemming from two major data breaches that exposed millions of guest records between 2019 and 2023. The United States District Court for the District of Nevada approved the settlement on June 18, 2025, under Judge Gloria M. Navarro. This settlement compensates individuals whose personal information—including Social Security numbers, passport numbers, and driver’s licenses—were stolen in one of the hospitality industry’s most significant cybersecurity incidents.
The settlement covers two distinct events: an unauthorized breach in July 2019 that exposed approximately 10.6 million guest records, and a ransomware attack in September 2023 that shut down MGM properties for 10 days and compromised at least 6 terabytes of customer data. If you stayed at any MGM property during or around these breach periods, you may be eligible for compensation ranging from $20 to $75, plus additional reimbursement for documented losses like fraud recovery costs. Most affected individuals will receive a flat payment based on which sensitive data was exposed to them, along with one year of free credit monitoring. However, the claim deadline has already passed as of June 3, 2025, so affected individuals should check their eligibility status immediately and understand what compensation tiers apply to them.
Table of Contents
- What Triggered the MGM Resorts Data Breach Class Action?
- How Many People Were Affected and What Data Was Exposed?
- The 2023 Ransomware Attack and Its Business Impact
- Settlement Compensation Structure and Payment Amounts
- Claiming Your Settlement and Missing Deadlines
- Credit Monitoring and Ongoing Identity Theft Protection
- Lessons for Consumers and Looking Forward
What Triggered the MGM Resorts Data Breach Class Action?
MGM Resorts, one of the world’s largest casino and hospitality operators, became the target of attackers in two separate incidents that exposed millions of guests’ most sensitive information. The first breach occurred on July 7, 2019, when an unauthorized individual gained access to MGM’s network and extracted personal details from approximately 10.6 million guest accounts. The data included names, addresses, phone numbers, email addresses, driver’s licenses, Social Security numbers, passport numbers, and dates of birth. In September 2023, MGM faced a far more disruptive attack when cybercriminals impersonated an IT administrator and gained entry to the company’s network. This attack triggered a 10-day operational shutdown affecting reservations systems, slot machines, room key systems, ATMs, and Wi-Fi across MGM properties nationwide.
The attack resulted in the theft of at least 6 terabytes of stored data and caused MGM over $100 million in losses. Criminal groups including Scattered Spider and ALPHV claimed responsibility for the September attack, and the incident became a case study in how sophisticated threat actors can cripple major operations through social engineering. These breaches illustrate a critical vulnerability in even the largest corporations: attackers don’t always need advanced zero-day exploits. In the 2023 case, simple credential theft through impersonation was enough to penetrate defenses and access massive amounts of data. This serves as a warning to consumers that even companies with substantial security budgets can be compromised, and personal information stored in corporate databases carries inherent risk.

How Many People Were Affected and What Data Was Exposed?
The two incidents combined affected millions of people, with the July 2019 breach being the larger of the two in terms of exposed records. The 10.6 million individuals affected by the 2019 breach had their most sensitive identifiers stolen, including government-issued IDs and Social Security numbers. In the 2023 ransomware attack, the exact number of individual records compromised was not publicly disclosed with the same precision, but at least 6 terabytes of data was stolen—a volume that undoubtedly included sensitive personal and financial information. The data exposed went well beyond what casual customers might assume a hotel would store. Beyond booking information, MGM’s database contained financial data, identification numbers, and travel patterns that could be used for identity theft, fraud, or social engineering attacks.
A person whose Social Security number and driver’s license information were stolen faces years of heightened risk for financial fraud, loan fraud, and identity theft—risks that don’t disappear after a few months. It’s important to understand that data breaches rarely result in immediate fraud. Instead, stolen credentials enter the dark web and may be used months or years later. The one-year credit monitoring offered as part of this settlement provides some protection, but it’s not a complete solution for the lifetime risk these individuals now face. Consumers who were affected should consider extending fraud monitoring beyond the one-year period and implementing credit freezes.
The 2023 Ransomware Attack and Its Business Impact
The September 2023 cyberattack stands out because it demonstrates the operational devastation that ransomware can cause to a major corporation. The attack didn’t just steal data—it paralyzed MGM’s operations. For 10 days, guests couldn’t make or modify reservations, couldn’t access their rooms through electronic key systems, couldn’t use ATMs, and the casino’s slot machines were offline. This wasn’t a quiet data exfiltration; it was a public shutdown that became international news. The attackers, believed to be affiliated with the Scattered Spider and ALPHV threat groups, successfully compromised an administrator account and used that access to deploy ransomware across MGM’s network.
MGM reported losses exceeding $100 million during the attack period alone, accounting for lost gaming revenue, operational disruptions, and incident response costs. The incident showed that even companies spending millions on cybersecurity can be vulnerable to social engineering and credential theft. What’s notable about this attack is that it moved beyond the typical data breach scenario. Rather than silently extracting data, the attackers demonstrated their access and control by crippling operations, creating both a financial incentive and a public demonstration of vulnerability. For consumers, this illustrates that data breaches today aren’t always subtle—sometimes the most damaging attacks are the ones that force companies to acknowledge the severity of the breach publicly.

Settlement Compensation Structure and Payment Amounts
The $45 million settlement establishes a tiered compensation system based on which categories of personal information were exposed to each affected individual. Individuals whose Social Security numbers or military identification numbers were exposed receive a $75 flat payment—the highest tier. Those whose passport numbers or driver’s licenses were compromised receive $50. Everyone else who qualifies as a class member but had less sensitive information exposed receives $20. Beyond the flat payments, the settlement includes a documented loss reimbursement program allowing individuals to submit claims for up to $15,000 in losses with proof.
This covers actual damages like fraud recovery costs, credit monitoring fees, identity theft legal fees, and other quantifiable harms resulting from the breach. To claim documented losses, individuals must provide receipts, statements, or professional invoices proving they incurred expenses due to fraud or identity theft tied to the data breach. All eligible class members receive one year of free financial account monitoring and fraud protection services. This provides some peace of mind but comes with an important limitation: one year of monitoring doesn’t address the lifetime risk of identity theft that these individuals now face. Consumers should plan to continue monitoring their credit reports well beyond the settlement’s one-year period and consider implementing credit freezes at all three major bureaus, which provide stronger protection against fraudulent account opening.
Claiming Your Settlement and Missing Deadlines
The deadline to submit a claim in the MGM Resorts data breach settlement was June 3, 2025—a date that has already passed. This creates an urgent situation for anyone who believes they were affected by either the 2019 or 2023 breach but hasn’t yet filed a claim. If you missed the deadline, you may have lost your right to compensation, though certain exceptions may exist for individuals who can demonstrate they didn’t receive proper notice. If you haven’t claimed yet, check the official MGM data settlement website at mgmdatasettlement.com immediately. The website will allow you to enter your information to determine if you’re part of the class and whether your claim was already processed.
Payments began being distributed on December 12, 2025, so some individuals have already started receiving their compensation. If you were entitled to a payment but didn’t claim before the deadline, your only option may be to contact the settlement administrator about potential relief for late claims, though success in this area is not guaranteed. For those who did file claims on time, payments were distributed starting December 12, 2025, and credit monitoring enrollment began on December 16, 2025. There’s a critical warning here: even if you received your settlement payment, you still need to actively enroll in the credit monitoring service. Missing the monitoring enrollment window could mean losing one year of free protection that you’re entitled to. Check your email for enrollment instructions and complete the process promptly.

Credit Monitoring and Ongoing Identity Theft Protection
The settlement includes one year of financial account monitoring for all eligible class members, but this deserves closer examination because many consumers misunderstand what monitoring actually does. Credit monitoring watches for unauthorized activity like new accounts opened in your name, fraudulent charges, or credit inquiries, but it doesn’t prevent fraud from occurring. It notifies you after the fact, which is valuable for damage control but not damage prevention. Given the sensitivity of the data exposed—particularly Social Security numbers and government IDs—affected individuals should take additional steps beyond the settlement’s monitoring. Placing a credit freeze with all three major credit bureaus (Equifax, Experian, and TransUnion) prevents anyone from opening new accounts without your permission.
This is free and more effective than monitoring alone. Additionally, consider setting up fraud alerts with the bureaus, which also cost nothing and require lenders to verify your identity before opening new credit in your name. The one-year monitoring window should be viewed as a starting point rather than a complete solution. After the year ends, continue monitoring your credit annually through free annual credit reports available at annualcreditreport.com, and consider paid credit monitoring services from reputable companies if you have other data breach exposures. This is especially important for individuals whose Social Security numbers were exposed, as that credential is the key to most types of identity theft.
Lessons for Consumers and Looking Forward
The MGM Resorts data breaches represent a broader reality in consumer data security: even massive corporations with substantial budgets cannot guarantee protection against sophisticated attackers. The 2023 ransomware attack, in particular, shows that social engineering and credential theft remain highly effective attack vectors, often more effective than trying to breach firewalls. This should inform how consumers think about the data they share with companies.
Going forward, consumers should assume that any data provided to businesses—hotels, retailers, financial institutions—is at some risk of exposure. While you can’t eliminate that risk, you can minimize your vulnerability by using unique passwords for each account, enabling multi-factor authentication where available, and monitoring your financial accounts regularly. The settlement serves as a reminder that data breaches are not hypothetical risks but recurring events that affect millions of people each year. Taking control of your credit security through freezes and monitoring isn’t paranoia—it’s appropriate protection in an environment where breaches are routine.
You Might Also Like
- Tyler Technologies Ransomware Data Breach Class Action
- Trinity Health Ransomware Data Breach Class Action
- Tenet Healthcare Data Breach Class Action
Open Settlements You Can Claim Now
Browse current class action settlements accepting claims — several require no proof of purchase:
