Wynn Resorts confirmed that an unauthorized third party stole employee data from its systems following claims by the ShinyHunters cybercrime group. The company said it activated incident response procedures, engaged external cybersecurity experts, and is monitoring for misuse; it also stated it has not seen evidence the data has been published. Wynn indicated the attacker claimed the stolen data was deleted, and the company is offering affected employees free credit monitoring and identity protection; Wynn also said the incident did not impact hotel operations or guest stays.
Reporting noted that Wynn’s entry on the ShinyHunters leak site was subsequently removed, a pattern commonly associated with an extortion payment or negotiated settlement, though Wynn has not confirmed any ransom payment. External commentary highlighted that attacker assurances of “deletion” are not verifiable and may indicate a completed extortion negotiation, and additional reporting indicated lawsuits have already been filed in connection with the breach.

See attribution, scope, and your downstream exposure.
8 events from the most recent confirmed update back to the earliest known activity.
Wynn Resorts disclosed that the personal information of 21,775 employees was compromised in the breach affecting its internal HR-related systems. The update clarified the scale of the incident while indicating employee data, not customer-facing systems, was impacted.
At least two lawsuits had already been filed against Wynn Resorts in connection with the employee data breach. The filings represented the first reported legal fallout from the incident.
By February 25, 2026, Wynn Resorts’ entry had been removed from the ShinyHunters leak site. Reporting noted this was widely interpreted as a possible sign that an extortion demand had been resolved, though Wynn did not confirm any ransom payment.
Following discovery of the breach, Wynn said it launched an internal investigation, activated incident response protocols, and engaged outside cybersecurity specialists to assist. The company also began offering affected employees free credit monitoring and identity protection services.
Wynn Resorts said an unauthorized third party stole certain employee data from its servers. The company stated the incident did not affect operations or guest stays and that it had not seen evidence of publication or misuse of the data.
Before Wynn’s public confirmation, the ShinyHunters extortion group posted Wynn Resorts on its data leak site, signaling a claim that data had been stolen. The listing brought the incident into public view and prompted wider reporting.
Wynn Resorts disclosed that the theft of employee data occurred during an October breach of its human resources systems. The update established the timeframe of the intrusion behind the incident that was publicly confirmed in February.
ShinyHunters claimed it gained access to Wynn Resorts as early as September 2025, allegedly by exploiting an Oracle PeopleSoft vulnerability and using a staff member’s credentials. This marks the earliest reported point of compromise in the incident.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
6 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourceteiss.co.uk
Open sourcescworld.com
Open sourcego.theregister.com
Open sourcedatabreaches.net
Open sourceteiss.co.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.