INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Wynn Resorts Staff Data Stolen, Attacker Claims Entire Information Deleted

| 2026-02-25 12:39 CRITICAL MEDIUM DATA BREACH
Executive Summary
AI-generated
On February 20, ShinyHunters claimed credit for a cyberattack on Wynn Resorts, stating that they had stolen employee data from the company's servers. The attackers assured Wynn that the stolen data had been deleted, which has led to speculation about whether a ransom was paid. Despite this, Wynn Resorts confirmed that no impact occurred on its operations or guest stays and is taking steps to strengthen systems against future incidents. As of now, there are approximately 2,000 employees affected by the breach, according to reports from Huntress security experts who have been working with Wynn to investigate the incident. The attackers' claim of data deletion has raised concerns among cybersecurity professionals about the reliability of such assurances in extortion negotiations.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Scattered SpiderScattered Spider
Target & Sectors
FIVE_EYES FIVE_EYES hospitalityhospitality
Incident Timeline
‎September 2025
Threat actors affiliated with Scattered Spider were arrested in connection with the 2024 cyberattacks on Caesars Entertainment and MGM Resorts.
threat_actor Scattered Spider
Intelligence Sources
The Register - Cybercrime 2026-02-25