X
Contacted by us, but you never reached out to the ITRC? Ignore it - it’s a scam!
Skip to content
ITRC logo white final
ITRC-logo-color-final.svg

Support the ITRC

Business Login

Call Now 888.400.5530

  • Victim Help Center
  • Solutions

    Prevent Identity Theft

    Protect your identity from theft and misuse.

    Recover My Identity

    Get direct assistance, a custom remediation plan, and resources if you're a victim.

    Protect My Business

    Explore our business service offerings today.

    Breach Alert

    Get information on the latest data compromises.

    Additional Support

    Vulnerable populations can get additional support to help protect their identity.

  • Resources

    Insights

    Get the latest information on identity crimes.

    Newsletter

    Stay up-to-date on the latest news and happenings from the ITRC.

    Reports

    Explore independent surveys and studies from the ITRC.

    Podcasts

    Hear or read the latest in data security and privacy, as well as identity compromise and crime.

    Events

    Explore upcoming events involving the ITRC.

    Newsroom

    Check out the ITRC’s hub for journalists and policy makers.

  • About the ITRC
  • Contact

Information from MGM Data Breach Ends Up on the Dark Web

Date: 02/20/2020

Home Help Center Information from MGM Data Breach Ends Up on the Dark Web

Updated 7/14/20 – The MGM Data Breach that occurred last summer is much larger than previously thought. According to threatpost, researchers have found 142 million personal details from former guests at the MGM Resorts hotels for sale on the Dark Web. The advertisement lists the guests’ personal details for more than $2,900.

Last summer, MGM Resorts disclosed an MGM data breach that affected around 10 million guests of the hotel company, including some fairly high-profile clients. The data, which included names, addresses, phone numbers and email addresses appears to have not included sensitive things like payment card information or Social Security numbers. However, that does not mean the information is useless, and it certainly has not stopped hackers from posting the stolen data for sale on the Dark Web.

There are a few different reasons why hackers might target a company or website. They might want to steal information, such as in the case of the MGM data breach, or install malicious software on the company’s servers. They might simply want the “credibility” of breaking into a secure site and bragging about it later, or even the ability to protect the public, as in the case of “white hat hackers” who infiltrate a company in order to show them their own defense weaknesses.

In the case of the MGM data breach, the goal seems to have been profit. The database of information—which included records that claim to belong to Justin Bieber, Twitter CEO Jack Dorsey, U.S. government officials and even a Secret Service agent—has now been discovered for sale online.

What can criminals do with this stolen information once they buy it from the hackers? After all, it does not contain any permanent identifiers or financial account records.

The end goal for this kind of sale is to grab up the email accounts and use them for targeted spam. It could be the annoying kind of spam that floods your inbox with ludicrous consumer offers, but it could also be the dangerous kind. For example, if the hacker wants to infiltrate a government computer, they might send an email with an embedded virus to a former guest with a .gov email address. In order to get the recipient to click the link, the email just has to look like it came from MGM Resorts—or another company the person does business with—and offer some plausible reason why the recipient should open the file.

From there, the malicious software, virus or even ransomware can be installed on the victim’s computer, and then the senders can move forward with whatever plan they intend.

In order to protect yourself from this kind of attack, there are some things you can do to be more proactive. No one can prevent every cyberattack, of course, but you can at least try to slow the bad guys down.

  1. Throwaway email account – Establish an email account that you use specifically for things like booking travel, online shopping or even signing up for gaming apps. There is no reason to use your work email or “official” email for those kinds of activities.
  2. Develop good habits – Never click a link, open an attachment or download a file that you were not specifically expecting. Even if it looks like it comes from someone you know or a company you do business with, it could be spoofed and therefore could be harmful.
  3. Stay up to date on data breaches – Any time there is a data breach and you are informed that your information may have been compromised, that should serve as another reminder that a wave of spam or fake emails is coming your way. Be on the lookout for anything unusual and stay away from those embedded dangers.

For more information on data breaches like the MGM data breach and what they could mean to you, go to idtheftcenter.org and check out the free Breach Clarity tool that helps consumers understand their risks and take the proper steps to protect their identity.

You might also like…

  • Microsoft Outlook “Cancellation Request” Email Scam Is The Latest to Look Out For 
  • Remote Workers Play Crucial Role in a Businesses Cybersecurity 
  • Password of the Day: Internet Fun or Dangerous Social Media Hoax?

How much information are you putting out there? It’s probably too much. To help you stop sharing Too Much Information, sign up for the In the Loop.

Get ID Theft News

Stay informed with alerts and newsletters from the Identity Theft Resource Center.

Global 100 2026 awards logo
ITRC 2026 Merit Award Winner
candid seal platinum 2026
Charity Navigator Badge Logo
Facebook-f X-twitter Youtube Linkedin-in Instagram
  • Support Our Mission
  • Our Mission
  • Contact
  • Media Resources
  • Cy Pres Awards
  • FAQ
  • Support Our Mission
  • Our Mission
  • Contact
  • Media Resources
  • Cy Pres Awards
  • FAQ
  • Privacy Policy
  • Live Chat Policy
  • Accessibility
© Copyright 2026 – Identity Theft Resource Center

This website was supported in part by grant number 15POVC-21-GK-01092-NONF and 15POVC-22-GK-01803-NONF, awarded by the Office for Victims of Crime, Office of Justice Programs, U.S. Department of Justice. The opinions, findings, and conclusions or recommendations expressed in this product are those of the contributors and do not necessarily represent the official position or policies of the U.S. Department of Justice. View more about our copyright info here.

  • Victim Help Center
  • Solutions
    • Prevent Identity Theft

      Protect your identity from theft and misuse.

    • Recover My Identity

      Get direct assistance, a custom remediation plan, and resources if you’re a victim.

    • Protect My Business

      Explore our business service offerings today.

    • Breach Alert

      Get information on the latest data compromises.

    • Additional Support

      Vulnerable populations can get additional support to help protect their identity.

  • Resources
    • Insights

      Stay up-to-date on the latest news and happenings from the ITRC.

    • Newsletter

      Stay up-to-date on the latest news and happenings from the ITRC.

    • Reports

      Explore independent surveys and studies from the ITRC.

    • Podcasts

      Hear or read the latest in data security and privacy, as well as identity compromise and crime.

    • Events

      Explore upcoming events involving the ITRC.

    • Newsroom

      Check out the ITRC’s hub for journalists and policy makers.

  • About the ITRC
  • Contact


  • Call Now 888.400.5530