Court approves $45 million preliminary settlement in MGM cyberattack lawsuit in Las Vegas
A $45 million settlement has been granted preliminary approval in two class-action lawsuits against MGM Resorts International, related to cyberattacks in July 2019 and September 2023. The final approval of this settlement is expected in June, pending its approval in U.S. District Court in Nevada, combining both cases of cyberattacks against MGM resorts.
In this global settlement, individuals whose Social Security numbers or military identification numbers were exposed will receive a $75 cash payment, while those with exposed passport numbers or driver’s licenses will get $50. Additionally, all class members included in the settlement may also receive benefits such as identity theft protection and credit monitoring services.
It was revealed in U.S. District Court that MGM holds a database of approximately 37 million customers, and this settlement aims to address the grievances of numerous MGM Resort patrons affected by the cyberattacks. Douglas McNamara, co-lead interim class counsel of Cohen Milstein, expressed satisfaction with the settlement, highlighting the vulnerability of the hotel and entertainment industries to cyber threats.
The cyberattacks on MGM Resorts caused significant disruptions across their operations, impacting financial transactions, online services, ATMs, parking access, reservation systems, email communications, and more. Following these attacks, MGM incurred damages estimated at around $100 million, although insurance coverage offered some relief. The company refused to pay any ransom demanded by the attackers, severely affecting their systems for nine days.
Subsequent actions against the cyberattack included an arrest made in England, where a 17-year-old suspect was apprehended by law enforcement officials. This arrest came around ten months after the attacks, with the suspect being released on bond. The involvement of hacker groups claiming responsibility for the cyberattacks was noted, adding complexity to the investigation into the incidents.
Furthermore, the aftermath of these cyberattacks led to legal disputes, including a lawsuit filed by MGM against the Federal Trade Commission (FTC) and its chairwoman at the time, Lina Khan. The lawsuit accused the FTC of violating MGM’s Fifth Amendment rights and failing to comply with conflict-of-interest guidelines. Khan’s stay at MGM Grand during the cyberattacks raised suspicions, eventually leading to her replacement as FTC chair by Andrew Ferguson.
In conclusion, the $45 million settlement reflects an important step towards resolving the fallout from the cyberattacks on MGM Resorts International. As the legal proceedings draw to a close, affected class members may soon receive compensation and necessary safeguards against identity theft, marking a significant development in this cybersecurity case.