CSIDB logo
Incident

Wynn Resorts

Incident posture

Attack window
Oct 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-09 03:20

Linked entities

Victim
Wynn Resorts
Threat actors
2 actors
Sources
1 source

Timeline

Occurred
Oct 2025
Discovered
Undetermined
Disclosed
Feb 2026
Resolved
Pending

Summary

Wynn Resorts disclosed that a breach affecting over 21,000 employees exposed personal data including Social Security numbers after attackers infiltrated its HR systems. The ShinyHunters group claimed to have taken more than 800,000 records and later removed the company from its leak site; the attackers demanded a ransom of over 22 bitcoin, valued at about $1.5 million. Researchers attribute the operation to a coalition known as Scattered Lapsus$ Hunters, which combines members of ShinyHunters, Lapsus$ and Scattered Spider. In response, the firm is providing affected staff with free credit monitoring and identity theft protection services.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

In October 2025, attackers targeted the human resources systems of Wynn Resorts and obtained employee data. The breach remained undisclosed until the ShinyHunters cybercrime group claimed to have stolen more than 800,000 records containing personally identifiable information, including Social Security numbers. Wynn Resorts confirmed in late February 2026 that hackers had accessed employee information. Subsequently, the company filed a data breach notification with the Maine Attorney General’s Office, stating that 21,775 employees were affected.

Cybersecurity researchers have attributed the operation to a supergroup known as Scattered Lapsus$ Hunters, which combines members of ShinyHunters, Lapsus$, and Scattered Spider. The attackers demanded a ransom of over 22 bitcoin, valued at approximately $1.5 million. After the demand, Wynn Resorts was removed from the ShinyHunters leak website, a development the article notes as suggesting a possible ransom payment. In response, Wynn began offering free credit monitoring and identity theft protection to all affected individuals.

The breach impacted more than twenty-one thousand employees, exposing their personal data to unauthorized access. Wynn Resorts is offering free credit monitoring and identity theft protection services to the affected employees. Related articles discuss T-Mobile's data breach filing, Salesforce customers targeted in a new campaign, and the European Commission reporting cyber intrusion.

Sources

Sources available to members: 1 source.

CSIDB