MGM Resorts settles class-action lawsuit over cyber attacks in 2019 and 2023
A couple from Tennessee changed their plans to celebrate their anniversary at the ARIA due to concerns about their data safety following cyber attacks on MGM Resorts. The class action lawsuit against MGM Resorts International regarding data breaches in 2019 and 2023 has reached a preliminary settlement of $45 million, approved by a federal judge. The hack in 2019 exposed personal information of around 37 million guests, resulting in the filing of eight separate class action lawsuits against MGM Resorts. These lawsuits were eventually consolidated into one collective legal action.
In 2023, hackers managed to access MGM Resort International’s network by posing as an IT administrator. This breach led to the exposure of sensitive customer details, including names, addresses, phone numbers, email addresses, dates of birth, driver’s license numbers, passport numbers, and in some instances, Social Security numbers. Subsequently, 14 class action lawsuits were initiated against MGM Resorts International following the 2023 incident. All these cases were later combined into the 2019 class action lawsuit.
As part of the preliminary settlement agreement, all members of the settlement class can claim compensation for losses incurred due to fraud or identity theft, professional fees including attorney, accountant, and credit repair fees, credit monitoring expenses, and costs related to initiating or terminating credit freezes with credit reporting agencies. Additionally, they can opt for a Tier Cash Payment based on the type of data exposed, ranging from $50 to $75. The settlement also allows for the submission of claims for financial account monitoring services that include identity theft protection and credit monitoring for a year.
Within 30 days of receiving preliminary approval, eligible settlement class members will be notified via email or a mailed postcard about the claim submission process, deadline, final hearing date, and website address for settlement information. Douglas J. McNamara, representing the plaintiffs, expressed satisfaction with the settlement, emphasizing the vulnerability of the hotel and entertainment industries to cyber threats.
McNamara also mentioned the 2023 cyber attack on Caesars Entertainment, Inc., orchestrated by the same hackers. In that incident, a group named “Scattered Spider” infiltrated an IT vendor to access the company’s network, compromising the personal information of over 65 million loyalty program members. Following the breach, the attackers demanded a $30 million ransom, to which Caesars reportedly paid $15 million. The company disclosed the event in a regulatory filing but was accused of not adequately informing customers about the breach in a timely manner.
Attorneys for Caesars Entertainment have moved to dismiss the case, refuting claims of negligence and lack of injury or damage attributable to the hack. As of the latest federal court docket, no further hearings have been scheduled regarding the matter.