Skip to content
Licensing & Regulation

Responding to a customer data breach: a playbook for operators

1. Situation Defined

Five major Nevada gaming operators have been hit by serious cyberattacks since September 2023: MGM Resorts, Caesars Entertainment, Boyd Gaming, Wynn Resorts and, as recently as March 2026, Station Casinos, which makes a customer data breach one of the least hypothetical crisis triggers a gambling operator’s board will face rather than a remote scenario worth only a paragraph in the risk register.

The pattern across the confirmed incidents is consistent enough to plan against: attackers used social engineering, most often a phone call to an IT help desk or outsourced support vendor convincing enough to bypass multi factor authentication, rather than a sophisticated technical exploit, and the data taken has centred on identity information, names, dates of birth, driver’s licence and in some cases Social Security or passport numbers, rather than payment card data, which operators have generally kept better isolated.

What separates a well handled incident from a badly handled one is not whether the attack happens, since the operators above range from the best resourced in the industry to targeted victims regardless, it is the speed and honesty of what happens in the days and weeks after discovery, and the clearest illustration of getting that wrong sits in the Station Casinos case, where a class action now alleges the company did not disclose the breach until eleven weeks after it was first discovered.

2. Immediate Response

In the first hours after a confirmed breach, the priority is containment without unnecessary operational self-harm, and the two 2023 incidents show the range of choices available. MGM shut systems down across the whole estate, which caused days of guest-facing outages across slot machines, digital key cards and reservations but limited the attackers’ ongoing access, while Caesars paid roughly fifteen million dollars in ransom, about half the attackers’ original demand, and avoided the extended visible outage MGM suffered.

Neither choice is free of consequence, and a board should have already agreed, before a crisis happens, which philosophy it would follow and why, rather than making that decision for the first time under pressure. Regulatory notification has a hard clock attached in the UK specifically: under LCCP condition 15.2.1, operators must report any security breach that adversely affects the confidentiality of customer data, or that prevents customer, staff or legitimate user access for more than twelve hours, to the Gambling Commission as soon as reasonably practicable and in any event within five working days, through the Commission’s eServices platform, covering the nature of the incident, systems affected, detection timeline, scope of impact, remediation steps and root cause.

That is a separate and concurrent obligation to any notification owed to the Information Commissioner’s Office under UK GDPR, so a single incident can trigger two regulatory conversations running at once, and a crisis team that has not mapped both in advance will lose time working that out live. Alongside regulatory notification, operators in every documented case set up a dedicated customer assistance channel, a toll free line, credit monitoring, in MGM’s case through Experian, and clear guidance on what data was and was not taken, since customers forgive an operator far more readily for being breached than for being vague about what happened to their information.

3. Risks and Contradictions

The single clearest risk in this playbook is not the breach itself, it is the gap between discovery and disclosure, and Station Casinos shows exactly how that gap becomes its own source of liability independent of the original attack: the breach was discovered in mid March 2026 but, according to the subsequent federal complaint, not disclosed until 21 May, and the same complaint alleges a single compromised employee account gave attackers access that then went undetected for an extended period despite operating, in the claimants’ words, overtly and noisily.

A board should treat that allegation as a live illustration of a genuine tension rather than dismiss it as one company’s failure: the instinct to delay disclosure until the investigation is complete and the full scope is understood is a reasonable one operationally, but it collides directly with a regulatory and legal environment that increasingly treats delay itself as misconduct, and Nevada’s own gaming regulator responded to the 2023 MGM and Caesars incidents by proposing to cut its cyber incident notification window from seventy two hours to twenty four.

A second contradiction sits in enforcement: there is no confirmed UK Gambling Commission fine specifically for data breach or data security handling failure among the largest recent penalties, which could be read by an operator as evidence the regulatory bar is low, but that reading would miss what the Commission’s own parallel, growing scrutiny of anti money laundering and social responsibility failings already suggests, that a regulator with the appetite to fine one category of operational failure heavily is unlikely to leave a comparable category unaddressed indefinitely.

Third, the two operators who paid and did not pay a ransom both survived the immediate crisis, which means a board cannot treat either choice as self-evidently correct, only as a decision with different, foreseeable trade-offs that need to be understood before the moment arrives.

4. Strategic Actions

Map every regulatory notification obligation triggered by a data incident, gambling regulator, data protection authority and any US state-specific requirement relevant to the business, into a single reference document the crisis team can execute against immediately, rather than researching obligations for the first time during an active incident.

Agree, at board level and in advance, the operator’s philosophy on ransom payment, containment scale, and the acceptable trade-off between operational continuity and limiting attacker access, so that the decision is not being made for the first time under pressure and time constraint.

Treat social engineering against IT help desks and outsourced support vendors as the primary attack vector to defend, given every major confirmed incident in this sector used that method rather than a purely technical exploit, and test staff and vendor response to it regularly.

Build a disclosure timeline discipline that assumes regulators and courts will judge the gap between discovery and notification as closely as they judge the breach itself, treating early, honest, incomplete disclosure as preferable to a delayed, complete one.

Separate payment card infrastructure as rigorously as possible from identity data storage, since every documented incident in this sector left payment data comparatively protected while identity data was the primary loss, suggesting existing card data segregation practices are working and should be extended to other sensitive data categories.

Establish the customer-facing response package, credit monitoring, a dedicated assistance line, and clear plain language communication about what was and was not taken, as a pre-built capability the operator can deploy within hours, not something assembled after the fact.

Assign individual, named accountability for crisis governance at senior management level, following the precedent set outside gambling by UK regulators fining a bank’s own former Chief Information Officer personally over a comparable operational resilience failure, so that accountability does not dissolve into a collective, unattributed corporate response.

5. International Lessons

Nevada’s regulatory response to its own sector’s 2023 incidents offers the most direct lesson available: rather than waiting for a slower federal process, the state’s Gaming Control Board moved to tighten its own notification rules, proposing to cut the incident reporting window from seventy two hours to twenty four, a reminder that a cluster of incidents in one jurisdiction tends to produce faster, stricter local rules than operators may be planning against.

The clearest lesson from outside gambling entirely comes from TSB Bank’s 2018 IT platform migration failure in the UK, which was not a hack but is one of the best documented crisis governance failures in a UK regulated sector: a botched migration left branch, telephone, online and mobile banking degraded or unavailable for a large share of 5.2 million customers, recovery dragged on for eight months, and the Financial Conduct Authority and Prudential Regulation Authority jointly fined TSB 48.65 million pounds in December 2022 for poor programme governance, inadequate risk management of a critical third party IT supplier, and insufficient senior management oversight, precisely the failures a gambling operator’s board should be testing its own crisis readiness against before an incident, not after one.

The contrast within gambling itself, between MGM and Caesars’ visible, costly 2023 incidents and Bragg Gaming’s contained, confidently communicated 2025 incident, where the company stated clearly and quickly that internal systems only were affected with no evidence of player data compromise, shows that scale of technical impact and scale of reputational damage are not the same thing, and that clear, fast, honest communication can separate the two.

6. Boardroom Questions

1. Have we mapped every regulatory notification obligation a data breach would trigger across every jurisdiction we operate in, and could our crisis team execute against that map within hours rather than researching it live?

2. Has the board agreed, in advance, our philosophy on ransom payment and the trade-off between operational continuity and limiting attacker access, or would that decision be made for the first time under pressure?

3. If a breach were discovered today, do we have a disclosure timeline discipline that would stand up to the same scrutiny Station Casinos is now facing over an eleven-week gap between discovery and notification.

Sources

1. Iowa Attorney General, MGM Resorts official data breach notification filing, 5 October 2023, https://www.iowaattorneygeneral.gov/media/cms/1052023_MGM_Resorts_0AFE2CF907B10.pdf

2. TechCrunch, MGM Resorts confirms hackers stole customers’ personal data during cyberattack, 6 October 2023, https://techcrunch.com/2023/10/06/mgm-resorts-admits-hackers-stole-customers-personal-data-cyberattack/

3. CDC Gaming Reports, SEC filing by MGM: Cyberattack will cost 100 million dollars in adjusted earnings, 6 October 2023, https://cdcgaming.com/sec-filing-by-mgm-cyberattack-will-cost-100-million-in-adjusted-earnings/

4. Bleeping Computer, Caesars Entertainment confirms ransom payment, customer data theft, 6 September 2023, https://www.bleepingcomputer.com/news/security/caesars-entertainment-confirms-ransom-payment-customer-data-theft/

5. Cybersecurity Dive, Caesars Entertainment says social-engineering attack behind August breach, 15 September 2023, https://www.cybersecuritydive.com/news/caesars-social-engineering-breach/695995/

6. Las Vegas Review-Journal, Station Casinos latest company to be victim of cyberattack, 2026, https://www.reviewjournal.com/business/casinos-gaming/locals-casino-operator-victim-of-cyberattack-3831852/ (Tier 2, cross-referenced against PlayUSA’s independent reporting of the same facts)

7. PlayUSA, Nevada’s Fifth Casino Cyberattack in Three Years Lands Station Casinos in Court, 2026, https://www.playusa.com/news/station-casinos-sued-2026-cyberattack/ (Tier 2, cross-referenced against the Las Vegas Review-Journal report and internally consistent on dates and facts)

8. Yogonet International, Nevada regulators advance tighter cyberattack reporting after 2023 MGM and Caesars breaches, 9 December 2025, https://www.yogonet.com/international/news/2025/12/09/116679-nevada-regulators-advance-tighter-cyberattack-reporting-after-2023-mgm-and-caesars-breaches (Tier 2, cross-referenced against parallel iGamingBusiness coverage of the same Nevada Gaming Control Board workshop)

9. Gambling Commission, Notification of information security breaches, accessed July 2026, https://www.gamblingcommission.gov.uk/licensees-and-businesses/guide/notification-of-information-security-breaches

10. Gambling Commission, LCCP Condition 15.2.1 – Reporting key events, accessed July 2026, https://www.gamblingcommission.gov.uk/licensees-and-businesses/lccp/condition/15-2-1-reporting-key-events

11. iGamingBusiness, Bragg Gaming Group seeks to allay fears over data breach incident, August 2025, https://igamingbusiness.com/tech-innovation/cybersecurity/bragg-allays-fears-cybersecurity-incident/

12. Financial Conduct Authority, TSB fined £48.65m for operational resilience failings, December 2022, https://www.fca.org.uk/news/press-releases/tsb-fined-48m-operational-resilience-failings

13. Bank of England, PRA fines the former Chief Information Officer of TSB Bank plc for a breach of the PRA’s Senior Manager Conduct Rules, April 2023, https://www.bankofengland.co.uk/news/2023/april/pra-fines-former-cio-of-tsb-bank-plc-for-breach-of-pra-senior-manager-conduct-rules