Multi-CloudIncident TeardownsRetrospectives

MGM Resorts Guest Data Leak (Feb 2020): 10 Million Records From a Cloud Server

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from February 2020, written in 2026 with the benefit of hindsight.

In February 2020, personal details of more than 10.6 million MGM Resorts hotel guests were posted on a hacking forum. MGM confirmed the data came from a 2019 incident involving unauthorized access to a cloud server.

What was exposed

Names, home addresses, phone numbers, email addresses and dates of birth. The list reportedly included celebrities, government officials and business travelers. MGM said no financial or password data was involved in the incident and that it had notified affected guests in 2019.

Why it mattered

The incident illustrated the long tail of data breaches: data stolen in 2019 surfaced publicly in 2020 and again later, being reused for phishing, fraud and social engineering. Contact details and dates of birth are often enough to impersonate someone to a help desk or customer service agent.

It also foreshadowed MGM's much more damaging 2023 ransomware attack — a different incident, but another example of a large hospitality company with an extensive digital footprint as a frequent target.

Lessons in hindsight

  • Know which cloud systems hold customer data and who owns them.
  • Minimize retained data. Guest records from years of stays create a large target.
  • Monitor for data appearing on criminal forums through threat intelligence services.
  • Assume leaked personal data will be used for social engineering — strengthen identity verification processes for customers and employees.

In hindsight

Hospitality companies hold rich personal data and face constant turnover in systems, vendors and staff. Data classification and minimization are as important as perimeter defenses — the data you no longer keep can't leak.

mgm data breach 2020MGM guest data2020

More on this story