Statement on MGM Resorts International: Setting the record straight Listed by alphv Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Statement on MGM Resorts International: Setting the record straight Listed by alphv Ransomware Group (reported September 11, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Ransomware groups continue to target large consumer-facing enterprises, using data theft and public leak-site postings to pressure organisations into negotiations. In this landscape, claims of breaches against major hospitality brands draw particular attention because of the volume of personal and operational information such companies routinely handle. On 11 September 2023, the ransomware group alphv listed MGM Resorts International, an American global hospitality and entertainment company, on its leak site under the heading “Statement on MGM Resorts International: Setting the record straight.”
Public detail remains limited. The listing asserts that internal files were exfiltrated in a ransomware attack; the number of people affected is unknown, and no further technical or financial particulars have been confirmed in the available record. The incident matters because any confirmed exposure of internal material from a major resort operator can affect guests, employees and business partners long after the initial disruption ends.
Inside the incident
According to the facts recorded for this event, alphv claimed responsibility by posting MGM Resorts International on its leak site on or around 11 September 2023. The group described the activity as a ransomware attack in which internal files were allegedly exfiltrated. No verified count of affected individuals has been published, nor have specific file names, system details, or the precise timeline of intrusion and discovery been disclosed in the material available here. The organisation’s own public statements beyond the existence of the listing are not part of the supplied record, so the full scope and method remain unconfirmed outside the group’s claim.
What is established is simply the listing itself and the characterisation of the data as internal files taken during a ransomware incident. Without independent corroboration of volume, content or dwell time, assessments of impact must stay within those bounds.
Inside alphv
Alphv, also widely known in public reporting as BlackCat, is a ransomware operation that emerged in late 2021 and has operated on a ransomware-as-a-service model. Affiliates gain access to victim networks, deploy the group’s encryptor, and exfiltrate data before encryption in many cases. The group has historically maintained a Tor-based leak site on which it names victims and, when negotiations stall, publishes samples or larger sets of stolen material. Public analyses have noted its use of custom malware written in Rust, double-extortion tactics, and a pattern of targeting organisations across multiple sectors, including hospitality, manufacturing and professional services.
In this instance the group’s leak-site entry constitutes an unverified claim that MGM Resorts International was breached and that internal files were taken. No additional statements attributed to alphv about this specific victim—beyond the listing title and the description of exfiltrated internal files—are contained in the facts. As with other alphv postings, the listing serves both as pressure and as a public assertion whose accuracy must be weighed against any later confirmation or denial by the organisation or independent investigators.
MGM Resorts International and its sector
MGM Resorts International is a major American hospitality and entertainment company that operates destination resorts, casinos, hotels and related leisure properties in the United States and internationally. Firms of this type manage large volumes of guest reservations, loyalty-programme data, payment information, employee records and internal operational documents. The sector as a whole has faced repeated ransomware and data-theft campaigns because the combination of high public visibility, complex IT environments spanning properties and third-party vendors, and the sensitivity of customer data creates both operational leverage and reputational risk for attackers.
A claimed breach at an organisation of this scale is consequential precisely because of that concentration of personal and business information. Even when the exact contents of any exfiltrated files remain unconfirmed, the mere assertion that internal material left the network raises questions for guests, staff and partners about potential downstream misuse.
What data was at risk
The available facts state only that internal files were exfiltrated in a ransomware attack. No inventory of specific data types—such as guest names, contact details, payment card data, employee records or proprietary documents—has been disclosed. Organisations in the hospitality and entertainment sector typically hold reservation histories, loyalty accounts, identification documents presented at check-in, payment card information, and human-resources files. Whether any of those categories were among the internal files claimed by alphv is unconfirmed.
Because the precise contents remain undisclosed, it is not possible to state as fact what categories of personal or corporate data were exposed. Readers should treat any assertion of specific data elements as speculative until corroborated by the organisation or by independent forensic reporting.
Why it matters
For individuals, the real-world risk centres on the possibility that personal information—if it was among the exfiltrated internal files—could later appear in criminal markets or be used for phishing, identity fraud or account takeover. Even without confirmed personal data, the disruption that often accompanies ransomware can affect booking systems, property operations and customer service, creating secondary inconvenience and uncertainty. For the organisation, a public leak-site listing carries reputational cost, potential regulatory scrutiny, and the expense of investigation, remediation and customer notification if personal data is later verified as compromised.
These consequences do not require sensational framing; they follow directly from the combination of a claimed data theft and the ordinary holdings of a large hospitality company. Until more detail is released, the prudent stance is to recognise the claim, monitor for official updates, and take basic protective steps with any accounts linked to MGM Resorts properties or loyalty programmes.
Were you affected?
If you have stayed at an MGM Resorts property, hold a loyalty account, or have been an employee or contractor, treat the alphv claim as a prompt to review your exposure rather than as confirmed proof that your data was taken. Change passwords on related accounts, enable multi-factor authentication where available, and monitor financial and email accounts for unusual activity. Official notifications, if any are required, would come from the company itself; check trusted channels rather than unsolicited messages. You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets, which provides one additional data point while the full scope of this incident remains limited in public reporting.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
JK Residential Services was hacked A lot of personal data was stolen Listed by alphv Ransomware GroupNej Inc was hacked Listed by alphv Ransomware GroupHenry Schein Inc - Henry's " LOST SHINE " Listed by alphv Ransomware GroupAutonomous Flight - @autonomousfly Listed by alphv Ransomware GroupLatest breaches
Publicly posted by alphv — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.