Breaches · 161 days ago
Wynn Resorts has disclosed that a breach affecting 21,775 employees likely resulted in the exfiltration of sensitive HR data, including Social Security numbers. The threat actor, linked to the ShinyHunters group, removed Wynn from their leak site after demanding a ransom exceeding 22 bitcoin, suggesting a probable ransom payment. The company’s filing with the Maine Attorney General states the attacker claimed to have deleted the data, but this does not guarantee the data is unrecoverable or unpublished elsewhere. The primary risk is downstream identity theft and privacy exposure for affected employees, not ongoing operational disruption. This incident highlights that removal from leak sites does not end the risk of personal data exposure or fraud long after the initial breach.
1 source covering this story
Wynn Resorts Says 21,000 Employees Affected by ShinyHunters Hack
The high-end casino and hotel operator has likely paid a ransom to avoid a data leak.
Part of the PlainSec briefing for 2026-04-08