Cyber Incident Victim: BetMGM
Date:
May 2022
Location:
United States of America
Summary
A cybersecurity incident involving BetMGM resulted in unauthorized access to certain patron records, compromising personal information including names, contact details, dates of birth, hashed Social Security numbers, account identifiers, and transaction-related data. The operator discovered the breach after an investigation with external security experts, determining that no passwords, account funds, or online systems were compromised. Affected individuals were offered complimentary credit monitoring and identity restoration services, while the company coordinated with law enforcement and implemented additional security measures to prevent future incidents.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On May 1, 2022, BetMGM experienced a data security incident involving unauthorized access to certain patron records. The company became aware of the breach on November 28, 2022, and promptly initiated an investigation with assistance from external security experts. Analysis determined that attackers obtained varying combinations of personal information including names, contact details (postal addresses, email addresses, telephone numbers), dates of birth, hashed Social Security numbers, account identifiers (player IDs and screen names), and transaction-related information. The compromise did not affect patron account funds or passwords, and BetMGM confirmed its online gaming and betting platforms remained fully operational throughout the incident. No evidence suggested ongoing unauthorized access to systems after the initial May 2022 intrusion.

BetMGM publicly disclosed the breach on December 21, 2022, notifying affected patrons via direct communication and establishing a dedicated toll-free hotline for inquiries. The company coordinated with law enforcement agencies and implemented additional security enhancements to its infrastructure. As remediation, BetMGM offered impacted U.S. and Canadian patrons complimentary two-year subscriptions to credit monitoring and identity restoration services. The operator directed customers to existing consumer protection resources including AnnualCreditReport.com and provided specific contact details for New Jersey residents to engage state consumer protection authorities. Internal investigations concluded the breach originated from external systems rather than BetMGM's core gaming platforms, with no indication that operational systems or financial transactions were compromised during the incident.
