MGM Class Action Lawsuit: $45M Data Breach Settlement Payouts

MGM Resorts International paid $45 million to settle a consolidated class action over two data breaches, one in July 2019 and a ransomware attack in September 2023. Judge Gloria M. Navarro of the U.S. District Court for the District of Nevada granted final approval to the MGM data breach settlement on June 18, 2025, and cash payments went out to approved claimants on December 12, 2025.1MGM Data Settlement. Tonya Owens, et al. v. MGM Resorts International et al. Settlement2Cohen Milstein. In Re MGM Resorts International Data Breach Litigation

Who Was Covered

The settlement class included customers and guests whose personal information was compromised in either incident.

The 2019 breach exposed roughly 10.6 million guest records dating back to 2017. Stolen data included names, email addresses, physical addresses, phone numbers, and dates of birth. The data was posted publicly on a hacking forum in February 2020.3Have I Been Pwned. MGM Resorts

The 2023 ransomware attack was larger and more damaging. Personal information belonging to approximately 37 million people was compromised. For most of that group, the exposed data was contact information and dates of birth. A smaller subset had more sensitive information taken, including Social Security numbers, passport numbers, and driver’s license numbers.4Forbes. MGM Ransomware Attack Update

How Much Claimants Could Receive

Compensation was tiered by the sensitivity of the data exposed, and each tier was subject to pro-rata adjustment based on the number of valid claims filed.1MGM Data Settlement. Tonya Owens, et al. v. MGM Resorts International et al. Settlement

  • $75 if your Social Security number or military identification number was stolen.
  • $50 if your passport number or driver’s license number was exposed.
  • $20 if your name, address, or date of birth was breached.
  • Up to $15,000 for documented out-of-pocket losses caused by the breach, with supporting documentation.

Class members who submitted a claim were also eligible for one year of free identity theft protection and financial account monitoring. That was in addition to any cash payment, not in place of it.1MGM Data Settlement. Tonya Owens, et al. v. MGM Resorts International et al. Settlement5Mashable. MGM Data Breach Settlement How to Claim

Key Dates

Preliminary approval came on January 22, 2025. The deadline to file a claim was June 3, 2025. Final approval followed on June 18, 2025.2Cohen Milstein. In Re MGM Resorts International Data Breach Litigation1MGM Data Settlement. Tonya Owens, et al. v. MGM Resorts International et al. Settlement

Approved cash payments were sent on December 12, 2025, using the method each claimant selected: check, PayPal, Venmo, direct deposit, or e-Mastercard. Enrollment emails for the credit and financial account monitoring benefit began going out on December 16, 2025.1MGM Data Settlement. Tonya Owens, et al. v. MGM Resorts International et al. Settlement6Talli.ai. MGM Resorts Data Breach Settlement

The claim window has closed. If you did not submit a claim by June 3, 2025, you are not eligible for a payment or the monitoring benefit from this settlement.

If You Filed a Claim

Kroll served as the claims administrator. Payments were pushed through the method chosen on the claim form. If a payment did not arrive, or if a monitoring enrollment email did not appear in mid-December 2025, the settlement website at mgmdatasettlement.com is the point of contact for status questions.1MGM Data Settlement. Tonya Owens, et al. v. MGM Resorts International et al. Settlement

What the Lawsuit Claimed

The consolidated complaint accused MGM of failing to implement reasonable data security practices and of violating its own privacy policy, which had promised to protect customer information. Legal claims included negligence, negligent misrepresentation, breach of implied contract, unjust enrichment, and violations of various state consumer protection laws. MGM moved to dismiss, but Judge Navarro largely denied that motion on November 2, 2022, allowing the case to move forward.7ClassAction.org. In Re MGM International Resorts Data Breach Litigation Settlement Agreement2Cohen Milstein. In Re MGM Resorts International Data Breach Litigation

After the 2023 attack, a second wave of lawsuits was consolidated as Tanya Owens, et al. v. MGM Resorts International, et al. In November 2024, that group was transferred to Judge Navarro so both sets of litigation could be resolved together. The parties filed a global settlement agreement on October 31, 2024.7ClassAction.org. In Re MGM International Resorts Data Breach Litigation Settlement Agreement

How the 2023 Attack Happened

The attackers, a group known as Scattered Spider working with the ALPHV/BlackCat ransomware operation, used social engineering rather than a technical exploit. They identified an MGM IT employee through LinkedIn, called the company’s help desk posing as that person, and convinced staff to reset the employee’s credentials. Within minutes they had network access.4Forbes. MGM Ransomware Attack Update8Morphisec. MGM Resorts ALPHV Spider Ransomware Attack

They encrypted more than 100 MGM server systems. Slot machines went dark at 30 MGM properties, digital hotel room keys stopped working, the company website and booking systems went offline, and guests were locked out of their rooms. Normal operations were not fully restored until September 19, nine days after the attack began. MGM refused to pay the ransom.9Cyberbit. Scattered Spider4Forbes. MGM Ransomware Attack Update

Criminal Charges and Regulatory Fallout

In November 2024, the U.S. Department of Justice unsealed charges against five people alleged to be members of Scattered Spider: Ahmed Hossam Eldin Elbadawy, Noah Michael Urban, Evans Onyeaka Osiebo, Joel Martin Evans, and Tyler Robert Buchanan, a U.K. national. Each of the four American defendants was charged with conspiracy to commit wire fraud, conspiracy, and aggravated identity theft. Buchanan faced those counts plus an additional wire fraud count. The charges covered a broader scheme targeting at least 12 U.S. organizations and roughly $11 million in cryptocurrency stolen from at least 29 victims between September 2021 and April 2023.10The Record. Five Scattered Spider Members Charged118 News Now. 5 Defendants Linked to Scattered Spider Hacker Group Behind 2023 MGM Caesars Cyberattacks

On the regulatory side, the Federal Trade Commission issued a Civil Investigative Demand to MGM on January 25, 2024, examining possible violations of Section 5 of the FTC Act, the Safeguards Rule under the Gramm-Leach-Bliley Act, and the Red Flags Rule under the Fair Credit Reporting Act. MGM challenged the demand and asked for the recusal of then-Chair Lina Khan. In late February 2025, new FTC Chairman Andrew Ferguson withdrew the CID, and the parties stipulated to dismissal without prejudice on February 28, 2025. MGM called the original demand “a dangerous overreach that sought to punish MGM Resorts for refusing to pay cybercriminals.”12The Record. Trump Admin Ends FTC Ransomware Case13Las Vegas Review-Journal. FTC Withdrawing Request for MGM Cyberattack Information

Canadian Residents

The U.S. settlement does not cover Canadian residents. Two separate proceedings handle those claims: Zuckerman v. MGM in the Superior Court of Québec for Québec residents, and Thandi v. MGM in the Supreme Court of British Columbia for Canadians outside Québec. Both are part of a collective Canadian settlement supported by a CAD $4 million fund covering the 2019 and 2023 incidents. Eligible class members may receive reimbursement for credit monitoring, up to CAD $20,000 for substantiated losses, or flat payments of CAD $150 to $300 for unsubstantiated losses, with possible increases depending on remaining funds. A settlement approval hearing in the British Columbia proceeding was scheduled for May 25, 2026, and in the Québec proceeding for May 20, 2026.14Newswire.ca. 2019 MGM Data Incident Notice of a Class Action Settlement Approval Hearing15Diamond Law. MGM Resorts Privacy Breach