Menu
Browse

Cyber Incident Victim: BetMGM

Date:

May 2022

Location:

United States of America

Summary

A cybersecurity incident involving BetMGM resulted in unauthorized access to certain patron records, compromising personal information including names, contact details, dates of birth, hashed Social Security numbers, account identifiers, and transaction-related data. The operator discovered the breach after an investigation with external security experts, determining that no passwords, account funds, or online systems were compromised. Affected individuals were offered complimentary credit monitoring and identity restoration services, while the company coordinated with law enforcement and implemented additional security measures to prevent future incidents.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On May 1, 2022, BetMGM experienced a data security incident involving unauthorized access to certain patron records. The company became aware of the breach on November 28, 2022, and promptly initiated an investigation with assistance from external security experts. Analysis determined that attackers obtained varying combinations of personal information including names, contact details (postal addresses, email addresses, telephone numbers), dates of birth, hashed Social Security numbers, account identifiers (player IDs and screen names), and transaction-related information. The compromise did not affect patron account funds or passwords, and BetMGM confirmed its online gaming and betting platforms remained fully operational throughout the incident. No evidence suggested ongoing unauthorized access to systems after the initial May 2022 intrusion.

Cyber Incident Image

BetMGM publicly disclosed the breach on December 21, 2022, notifying affected patrons via direct communication and establishing a dedicated toll-free hotline for inquiries. The company coordinated with law enforcement agencies and implemented additional security enhancements to its infrastructure. As remediation, BetMGM offered impacted U.S. and Canadian patrons complimentary two-year subscriptions to credit monitoring and identity restoration services. The operator directed customers to existing consumer protection resources including AnnualCreditReport.com and provided specific contact details for New Jersey residents to engage state consumer protection authorities. Internal investigations concluded the breach originated from external systems rather than BetMGM's core gaming platforms, with no indication that operational systems or financial transactions were compromised during the incident.

Sources
Sources available to members
1 source