Wynn Resorts Confirms Data Breach After Hackers Remove It From Leak Site - SecurityWeek
SecurityWeekArchived Apr 07, 2026✓ Full text saved
Wynn Resorts Confirms Data Breach After Hackers Remove It From Leak Site SecurityWeek
Full text archived locally
✦ AI Summary· Claude Sonnet
Las Vegas-based high-end casino and hotel operator Wynn Resorts has confirmed that hackers have stolen employee data.
“We have learned that an unauthorized third party acquired certain employee data,” the company told SecurityWeek. “Upon discovery, we immediately activated our incident response protocols and launched a thorough investigation with the help of external cybersecurity experts.”
“This incident has had no impact on our guest experience, our operations or our physical properties, which are all fully operational and open for business,” it added.
Wynn Resorts named on ShinyHunters website
Wynn Resorts was added to the ShinyHunters data leak website on February 20, when the hackers claimed to have stolen more than 800,000 records containing personally identifiable information (including SSNs) and employee data.
“This is a final warning to reach out by 24 Feb 2026 before we leak along with several annoying (digital) problems that’ll come your way. Make the right decision, don’t be the next headline,” the hackers said in a message addressed to Wynn Resorts at the time.
Wynn Resorts has since been removed from the ShinyHunters website and the company’s statement suggests a ransom may have been paid.
“The unauthorized third party has stated that the stolen data has been deleted,” the company said in an emailed statement. “We are monitoring and to date have not seen any evidence that the data has been published or otherwise misused.”
SecurityWeek has asked Wynn for confirmation that a ransom has indeed been paid, but the company declined to comment.
The Register previously reported that the cybercrime group had demanded a ransom of 22.34 bitcoin (roughly $1.5 million).
The luxury hospitality and gaming company said its investigation is ongoing, but it has decided to offer credit monitoring and identity protection services to affected employees.
“The security and confidentiality of our employees, as well as our guest data, is our top priority,” Wynn said. “While no company can ever eliminate the risk of a cyberattack, we are taking appropriate steps and working with industry-leading third-party IT advisors to strengthen our systems to protect against future incidents.”
The ShinyHunters group is believed to have targeted more than 100 organizations in recent campaigns, which often involve vishing and compromised SSO credentials.
The cybercriminals have named several major companies on their leak site in recent weeks, including Figure, Betterment, Crunchbase, SoundCloud, and Panera Bread.
Related: Ad Tech Company Optimizely Targeted in Cyberattack
Related: Ransomware Groups May Pivot Back to Encryption as Data Theft Tactics Falter
Related: PayPal Data Breach Led to Fraudulent Transactions
WRITTEN BY
Eduard Kovacs
Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.
More from Eduard Kovacs
T-Mobile Sets the Record Straight on Latest Data Breach Filing
Apple Rolls Out DarkSword Exploit Protection to More Devices
Cybersecurity M&A Roundup: 38 Deals Announced in March 2026
Toy Giant Hasbro Hit by Cyberattack
Exploited Zero-Day Among 21 Vulnerabilities Patched in Chrome
FBI Warns of Data Security Risks From China-Made Mobile Apps
Google Addresses Vertex Security Issues After Researchers Weaponize AI Agents
Censys Raises $70 Million for Internet Intelligence Platform
Latest News
Wynn Resorts Says 21,000 Employees Affected by ShinyHunters Hack
Google DeepMind Researchers Map Web Attacks Against AI Agents
Guardarian Users Targeted With Malicious Strapi NPM Packages
North Korean Hackers Target High-Profile Node.js Maintainers
Fortinet Rushes Emergency Fixes for Exploited Zero-Day
European Commission Confirms Data Breach Linked to Trivy Supply Chain Attack
TrueConf Zero-Day Exploited in Asian Government Attacks
In Other News: ChatGPT Data Leak, Android Rootkit, Water Facility Hit by Ransomware
Trending
Webinar: Securing Fragile OT In An Exposed World
March 10, 2026
Get a candid look at the current OT threat landscape as we move past "doom and gloom" to discuss the mechanics of modern OT exposure.
Register
Webinar: Why Automated Pentesting Alone Is Not Enough
April 7, 2026
Join our live diagnostic session to expose hidden coverage gaps and shift from flawed tool-level evaluations to a comprehensive, program-level validation discipline.
Register
People on the Move
Scott Goree has been appointed Senior Vice President of Channel and Alliances at Delinea.
Kai has named Nick Degnan as Chief Revenue Officer.
Joe Sullivan has been appointed Strategic Advisor at cloud security firm Upwind.
More People On The Move
Expert Insights
The Next Cybersecurity Crisis Isn’t Breaches—It’s Data You Can’t Trust
Data integrity shouldn’t be seen only through the prism of a technical concern but also as a leadership issue. (Steve Durbin)
Why Agentic AI Systems Need Better Governance – Lessons From OpenClaw
Agentic AI platforms are shifting from passive recommendation tools to autonomous action-takers with real system access, (Etay Maor)
The Human IOC: Why Security Professionals Struggle With Social Vetting
Applying SOC-level rigor to the rumors, politics, and 'human intel' can make or break a security team. (Joshua Goldfarb)
How To 10x Your Vulnerability Management Program In The Agentic Era
The evolution of vulnerability management in the agentic era is characterized by continuous telemetry, contextual prioritization and the ultimate goal of agentic remediation. (Nadir Izrael)
SIM Swaps Expose A Critical Flaw In Identity Security
SIM swap attacks exploit misplaced trust in phone numbers and human processes to bypass authentication controls and seize high-value accounts. (Torsten George)
Flipboard
Reddit
Whatsapp
Email