
Las Vegas-based MGM Resorts International has agreed to pay $45 million to settle a class-action lawsuit stemming from two major data breaches that compromised the personal information of millions of customers in 2019 and 2023. The settlement, filed for preliminary approval in the U.S. District Court for Nevada last week, marks a significant resolution to allegations of inadequate data security practices by the entertainment and hospitality giant.
The two breaches, which collectively affected approximately 37 million individuals, exposed sensitive customer data, including phone numbers, addresses, Social Security numbers, passport details, and driver’s license numbers. The stolen information was later found for sale online.
The 2019 breach involved the theft of personal information such as driver’s license numbers, passport numbers, and customer addresses. In 2023, MGM Resorts suffered a ransomware attack four years later that turned off critical operating systems for several days. Plaintiffs alleged that customer information was also compromised during the latter attack.
In a statement regarding the settlement, Douglas J. McNamara, Co-Lead Interim Class Counsel and partner at Cohen Milstein, expressed satisfaction with the outcome. “On behalf of millions of MGM Resort customers, I’m very pleased with this settlement,” McNamara said. He also noted that the hospitality and entertainment sectors remain prime targets for cyberattacks, citing a similar incident involving Caesars Entertainment, Inc. in 2023.
Under the settlement terms, eligible class members will receive compensation and access to identity theft protection services. Individuals whose Social Security or military identification number was exposed may claim $75, while those whose passport number or driver’s license was compromised are eligible for $50. All class members can also opt for identity theft protection and credit monitoring services.
For those who can demonstrate documented financial losses related to the breaches—such as unreimbursed expenses from identity theft or fees for credit repair—payments could reach up to $15,000 per individual.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543