Msspalert Wynn Resorts Cyberattack Exposes 800,000 Employee Records
Article Content
- •Wynn Resorts suffered a cyberattack exposing 800,000 employee records.
- •The ShinyHunters group demanded a $1.5 million ransom in Bitcoin.
- •Security Validation partnered with Stellar Cyber to enhance threat detection capabilities.
Wynn Resorts confirmed a cyberattack by the ShinyHunters group, which occurred in September 2025, resulting in the theft of 800,000 employee records, including sensitive data like Social Security numbers and email addresses. The attackers demanded a ransom of $1.5 million in Bitcoin, threatening to release the stolen data if their demands were not met. This incident is part of a troubling trend in the hospitality sector, which has seen similar attacks on major players like MGM and Caesars. Security Validation, a managed security service provider (MSSP), has partnered with Stellar Cyber to enhance its security capabilities in response to such threats. The partnership aims to improve threat detection and response times, addressing the vulnerabilities inherent in the hospitality industry. Analysts have noted that the sector is often underprepared for sophisticated cyber threats, exacerbated by decentralized operations and high employee turnover. The attack highlights ongoing challenges in cybersecurity for hospitality businesses, which require robust monitoring and rapid incident response.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Caesars Casinos in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…