MGM Resorts and Caesars Entertainment both reported that customer or loyalty-member personal information was accessed in September 2023, but their SEC filings described different operational effects and different levels of detail. MGM reported service disruption followed by restoration and gave a preliminary estimate of financial impact. Caesars described a social-engineering attack involving an outsourced IT support vendor and said customer-facing operations continued without disruption.
What MGM reported in its October 5 filing
MGM’s October 5, 2023 Form 8-K said the company detected a cybersecurity issue affecting certain U.S. systems and shut systems down to mitigate risk to customer information. MGM reported that domestic-property operations had returned to normal and virtually all guest-facing systems had been restored by the time of the filing.
Customer information MGM said was obtained
MGM said criminal actors obtained personal information belonging to some customers who had transacted with the company before March 2019. The listed information included names, contact information, gender, dates of birth, and driver’s-license numbers. For a limited number of customers, Social Security and passport numbers were also obtained.
MGM said it did not believe customer passwords, bank-account numbers, or payment-card information were obtained. It also reported no evidence at that time that the data had been used for identity theft or account fraud. Those were MGM’s findings when it filed, not a guarantee against future misuse.
#1 Best Overall
The company said it planned to notify affected individuals and provide free identity protection and credit monitoring. Its customer notice described the affected information categories, notification process, and monitoring offer.
MGM’s preliminary financial estimate
MGM estimated approximately $100 million of negative impact to Adjusted Property EBITDAR for the Las Vegas Strip Resorts and Regional Operations, collectively, in September 2023. It also reported less than $10 million in one-time third-party expenses in the third quarter, including technology consulting and legal fees. MGM called these figures preliminary and said the full scope of costs and effects had not been determined; the $100 million figure was not a final total-loss estimate.
What Caesars reported in its September 14 filing
Caesars’ September 14, 2023 Form 8-K said suspicious IT-network activity resulted from a social-engineering attack on an outsourced IT support vendor. The filing said that on September 7, Caesars determined an unauthorized actor had acquired a copy of, among other data, its loyalty-program database.
Member information and customer operations
Caesars said the loyalty database included driver’s-license numbers and/or Social Security numbers for a significant number of members. Its investigation into whether additional sensitive information was included was ongoing. The company said it had no evidence that member passwords or PINs, bank-account information, or payment-card information were acquired.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Caesars said it had not seen evidence at filing time of further sharing, publication, or misuse of the acquired data. It also said customer-facing operations—including physical properties and online and mobile gaming—continued without disruption.
The filing described Caesars’ engagement of cybersecurity firms, notifications to law enforcement and state gaming regulators, credit monitoring and identity-theft protection for loyalty members, and corrective measures with the outsourced vendor. These are company-reported actions, not independent verification of their effectiveness.
Rank #4
Caesars did not quantify a final cost
Caesars said it had incurred incident-related expenses and could incur more, but had not determined the full scope of costs or related effects, including possible insurance or indemnification offsets. It did not give a final cost in this filing and said it did not expect a material effect on its financial condition or results at that time.
How the disclosures differ
| Disclosure point | MGM | Caesars |
|---|---|---|
| Filing | October 5, 2023 Form 8-K; reported an issue first publicly identified in September. | September 14, 2023 Form 8-K; reported suspicious activity and a September 7 determination that data had been acquired. |
| Reported access route | The cited October filing describes unauthorized activity and system shutdowns but does not identify the initial access route. | Social-engineering attack on an outsourced IT support vendor. |
| Reported personal information | Names, contact information, gender, dates of birth, and driver’s-license numbers; Social Security and passport numbers for a limited number of customers. | Loyalty database included driver’s-license numbers and/or Social Security numbers for a significant number of members; investigation of other data was ongoing. |
| Customer-facing operations | Reported disruption, followed by restored domestic operations and virtually all guest-facing systems by October 5. | Said physical, online, and mobile customer-facing operations continued without disruption. |
| Financial disclosure | Preliminary estimate of approximately $100 million negative Adjusted Property EBITDAR impact and less than $10 million of one-time expenses. | Costs and possible insurance or indemnification offsets remained undetermined; no final cost was quantified. |
| Customer assistance | Planned notification and free identity protection and credit monitoring for affected people. | Credit monitoring and identity-theft protection for loyalty members. |
The filings were made at different stages of the companies’ investigations and do not establish that one incident was more severe overall. They also do not establish a common threat actor or a ransom payment.
Best Value
What the SEC’s incident-disclosure rule requires
The SEC announced cybersecurity disclosure rules on July 26, 2023. Under current Item 1.05 requirements, a registrant generally must file a Form 8-K within four business days after determining that a cybersecurity incident is material. The filing describes material aspects of the incident’s nature, scope, and timing, as well as its material or reasonably likely material impact. The deadline is tied to the materiality determination—not automatically to the day an incident is discovered—and that determination must be made without unreasonable delay.
A limited delay is possible if the U.S. Attorney General determines that immediate disclosure would pose a substantial risk to national security or public safety and notifies the SEC in writing. The rules also require annual disclosures about cybersecurity risk management, strategy, and governance. The SEC’s rule announcement and cybersecurity disclosure guidance explain the requirements.
These two 2023 filings should not be confused with standardized Item 1.05 incident reports under the later compliance regime. MGM furnished information under Form 8-K Items 2.02 and 7.01; Caesars used Item 8.01. The rules became effective in September 2023, but incident-reporting compliance for registrants other than smaller reporting companies began December 18, 2023. SEC Chair Gary Gensler summarized the investor-disclosure rationale when the rules were announced: “Whether a company loses a factory in a fire — or millions of files in a cybersecurity incident — it may be material to investors.”
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.




