Saudi Press

Saudi Arabia and the world
Sunday, Nov 09, 2025

Exclusive: Details of 10.6 million MGM hotel guests posted on a hacking forum

Exclusive: Details of 10.6 million MGM hotel guests posted on a hacking forum

MGM Resorts said security incident took place last summer and notified impacted guests last year.

The personal details of more than 10.6 million users who stayed at MGM Resorts hotels have been published on a hacking forum this week.

Besides details for regular tourists and travelers, included in the leaked files are also personal and contact details for celebrities, tech CEOs, reporters, government officials, and employees at some of the world's largest tech companies.

ZDNet verified the authenticity of the data today, together with a security researcher from Under the Breach, a soon-to-be-launched data breach monitoring service.

A spokesperson for MGM Resorts confirmed the incident via email.


WHAT WAS EXPOSED

According to our analysis, the MGM data dump that was shared today contains personal details for 10,683,188 former hotel guests.

Included in the leaked files are personal details such as full names, home addresses, phone numbers, emails, and dates of birth.

ZDNet reached out to past guests and confirmed they stayed at the hotel, along with their timeline, and the accuracy of the data included in the leaked files.

We got confirmation from international business travelers, reporters attending tech conferences, CEOs attending business meetings, and government officials traveling to Las Vegas branches.


MGM RESORTS SAYS THEY NOTIFIED CUSTOMERS LAST YEAR

Once we verified the data, ZDNet also reached out to MGM Resorts.

Within an hour after we reached out to the company, we were in a conference call with the hotel chain's security team. Within hours, the MGM Resorts team was able to verify the data and track it to a past security incident.

An MGM spokesperson told ZDNet the data that was shared online this week stems from a security incident that took place last year.

"Last summer, we discovered unauthorized access to a cloud server that contained a limited amount of information for certain previous guests of MGM Resorts," MGM told ZDNet.

"We are confident that no financial, payment card or password data was involved in this matter."

TechRepublic Premium tools: Hiring Kit: Security architect | Access management policy | Malware response checklist | Security Response Policy

The hotel chain said it promptly notified all impacted hotel guests in accordance with applicable state laws.

While we were not able to track down one of these notifications personally, some users appear to have posted online about receiving one in August last year.

Also, MGM Resorts told us it retained two cybersecurity forensics firms to conduct an internal investigation into last year's server exposure.

"At MGM Resorts, we take our responsibility to protect guest data very seriously, and we have strengthened and enhanced the security of our network to prevent this from happening again," the company said.

According to Irina Nesterovsky, Head of Research at threat intel firm KELA, the data of MGM Resorts hotel guests had been shared in some closed-circle hacking forums since at least July, last year. The hacker who released this information is believed to have an association, or be a member of GnosticPlayers, a hacking group that has dumped more than one billion user records throughout 2019.


A POTENTIAL DANGER OF SIM SWAPPING AND SPEAR-PHISHING

However, while MGM's security incident went under the radar last year, the publication of this data dump on a very popular and openly accessibly hacking forum this week has brought it to many other hackers' attention.

Under the Breach, the company that spotted this leak and notified this reporter was the one who highlighted the highly sensitive nature of the breach.

The leaked data is a treasure trove for contact details for many high-profile users, working for big tech firms and governments all over the world. These users now face a higher risk of receiving spear-phishing emails, and being SIM swapped, Under the Breach told ZDNet.

Twitter CEO Jack Dorsey, pop star Justin Bieber, and DHS and TSA officials are some of the big names Under the Breach spotted in the leaked files.

MGM Resorts told ZDNet that the data was old. We can confirm this statement as from all the hotel guests we called today, none stayed at the hotel past 2017. Some of the phone numbers we called were disconnected, but many were also valid, and the right person answered the phone.

The size and the severity of this MGM Resorts security incident pale in comparison to the massive data breach that impacted Marriott hotels in 2017 when the details of hundreds of millions of users were stolen by Chinese state-sponsored hackers.

Newsletter

Related Articles

Saudi Press
0:00
0:00
Close
Saudi Arabia Sets Pre-Conditions for Israel Normalisation Ahead of Trump Visit
MrBeast’s ‘Beast Land’ Arrives in Riyadh as Part of Riyadh Season 2025
Cristiano Ronaldo Asserts Saudi Pro League Outperforms Ligue 1 Amid Scoring Feats
AI Researchers Claim Human-Level General Intelligence Is Already Here
Saudi Arabia Pauses Major Stretch of ‘The Line’ Megacity Amid Budget Re-Prioritisation
Saudi Arabia Launches Instant e-Visa Platform for Over 60 Countries
Dick Cheney, Former U.S. Vice President, Dies at 84
Saudi Crown Prince to Visit Trump at White House on November Eighteenth
Trump Predicts Saudi Arabia Will Normalise with Israel Ahead of 18 November Riyadh Visit
Entrepreneurial Momentum in Saudi Arabia Shines at Riyadh Forward 2025 Summit
Saudi Arabia to Host First-Ever International WrestleMania in 2027
Saudi Arabia to Host New ATP Masters Tournament from 2028
Trump Doubts Saudi Demand for Palestinian State Before Israel Normalisation
Viral ‘Sky Stadium’ for Saudi Arabia’s 2034 World Cup Debunked as AI-Generated
Deal Between Saudi Arabia and Israel ‘Virtually Impossible’ This Year, Kingdom Insider Says
Saudi Crown Prince to Visit Washington While Israel Recognition Remains Off-Table
Saudi Arabia Poised to Channel Billions into Syria’s Reconstruction as U.S. Sanctions Linger
Smotrich’s ‘Camels’ Remark Tests Saudi–Israel Normalisation Efforts
Saudi Arabia and Qatar Gain Structural Edge in Asian World Cup Qualification
Israeli Energy Minister Delays $35 Billion Gas Export Agreement with Egypt
Fincantieri and Saudi Arabia Agree to Build Advanced Maritime Ecosystem in Kingdom
Saudi Arabia’s HUMAIN Accelerates AI Ambitions Through Major Partnerships and Infrastructure Push
IOC and Saudi Arabia End Ambitious 12-Year Esports Games Partnership
CSL Seqirus Signs Saudi Arabia Pact to Provide Cell-Based Flu Vaccines and Build Local Production
Qualcomm and Saudi Arabia’s HUMAIN Team Up to Deploy 200 MW AI Infrastructure
Saudi Arabia’s Economy Expands Five Percent in Third Quarter Amid Oil Output Surge
China’s Vice President Han Zheng Meets Saudi Crown Prince as Trade Concerns Loom
Saudi Arabia Unveils Vision for First-Ever "Sky Stadium" Suspended Over Desert Floor
Francis Ford Coppola Auctions Luxury Watches After Self-Financed Film Flop
US and Qatar Warn EU of Trade and Energy Risks from Tough Climate Regulation
‘No Kings’ Protests Inflate Numbers — But History Shows Nations Collapse Without Strong Executive Power
Ofcom Rules BBC’s Gaza Documentary ‘Materially Misleading’ Over Narrator’s Hamas Ties
"The Tsunami Is Coming, and It’s Massive": The World’s Richest Man Unveils a New AI Vision
Yachts, Private Jets, and a Picasso Painting: Exposed as 'One of the Largest Frauds in History'
AI and Cybersecurity at Forefront as GITEX Global 2025 Kicks Off in Dubai
EU Deploys New Biometric Entry/Exit System: What Non-EU Travelers Must Know
Ex-Microsoft Engineer Confirms Famous Windows XP Key Was Leaked Corporate License, Not a Hack
China’s lesson for the US: it takes more than chips to win the AI race
Israel and Hamas Agree to First Phase of Trump-Brokered Gaza Truce, Hostages to Be Freed
The Davos Set in Decline: Why the World Economic Forum’s Power Must Be Challenged
Wave of Complaints Against Apple Over iPhone 17 Pro’s Scratch Sensitivity
Syria Holds First Elections Since Fall of Assad
Altman Says GPT-5 Already Outpaces Him, Warns AI Could Automate 40% of Work
Trump Organization Teams with Saudi Developer on $1 Billion Trump Plaza in Jeddah
Electronic Arts to Be Taken Private in Historic $55 Billion Buyout
Colombian President Petro Vows to Mobilize Volunteers for Gaza and Joins List of Fighters
Nvidia and Abu Dhabi’s TII Launch First AI-&-Robotics Lab in the Middle East
UK, Canada, and Australia Officially Recognise Palestine in Historic Shift
New Eye Drops Show Promise in Replacing Reading Glasses for Presbyopia
Dubai Property Boom Shows Strain as Flippers Get Buyer’s Remorse
×