Trump administration ends FTC’s ransomware data breach case against MGM Resorts
美国联邦贸易委员会(FTC)关闭了对美高梅集团(MGM Resorts International)的调查案,该案件源于2023年的一次勒索软件攻击导致的数据泄露。美高梅拒绝配合调查,但在特朗普政府上台后,FTC撤销了调查请求。双方同意撤诉,结束了法律争议。此次攻击影响了美高梅旗下多个酒店,并导致超过3700万客户的资料被盗。 2025-3-10 18:0:55 Author: therecord.media(查看原文) 阅读量:5 收藏

The Federal Trade Commission (FTC) shuttered its case against MGM Resorts International centered on the company’s handling of personal data stolen during a 2023 ransomware attack.

The FTC filed a Civil Investigative Demand (CID) in January 2024 seeking answers to dozens of questions about the ransomware attack that involved customer and employee data as well as troves of business information.

The FTC specifically wanted information on the company’s compliance with Section 5 of the FTC Act, the Safeguards Rule under the Gramm-Leach-Bliley Act and the Red Flags Rule under the Fair Credit Reporting Act.

MGM Resorts International repeatedly refused to provide the information and the FTC in June 2024 filed a lawsuit in Nevada to enforce the CID. The two sides went back and forth in court for months, with the casino giant demanding FTC chair Lina Khan recuse herself because she happened to be staying at a Las Vegas hotel owned by the company at the time of the cyberattack. 

The company also petitioned to have the case moved to Washington, D.C. and questioned whether the FTC had jurisdiction in the case at all. 

But on February 28, court filings confirmed that with the Trump administration taking office, the FTC’s CID had been withdrawn, making the court cases “moot” according to lawyers for both sides.

Documents filed in federal courts in Nevada and Washington, D.C. say MGM was contacted by the FTC on February 26 to say it intended to terminate the litigation around the CID. 

Over the last week, the two sides filed motions to dismiss many of the cases.

“The Petitioner, the Federal Trade Commission, and the Respondent, MGM Resorts International, hereby stipulate and agree that the above-captioned action be dismissed without prejudice, with each party to bear its own costs and attorneys’ fees,” the two sides said.

The two sides plan to submit a joint status report “on or before March 21” to provide further updates on the efforts to dismiss or withdraw the remaining legal filings. 

The filings bring an end to much of the legal controversy that surrounded the ransomware attack on MGM Resorts International, which owns multiple high-profile hotels across Las Vegas, including Mandalay Bay, the Bellagio, the Cosmopolitan and the Aria. Hotels were unable to accept credit cards and guests were left scrambling to find alternative housing while staff at multiple casinos had to calculate slot machine losses and wins by hand. All of the digital systems used to manage the casinos and hotels were brought down by the ransomware attack.

In January, the casino giant agreed to pay $45 million to settle multiple class action lawsuits related to a data breach in 2019 and the 2023 ransomware attack. Lawyers for the victims said more than 37 million customers of MGM Resorts International had information stolen during the cyberattack in July 2019 and the September 2023 ransomware attack.

Ransomware hackers connected to the now-defunct BlackCat/Alphv gang eventually took credit for the attack. The company said in regulatory filings that it lost about $100 million due to the incident.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

Jonathan Greig

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.


文章来源: https://therecord.media/trump-admin-ends-ftc-ransomware-case
如有侵权请联系:admin#unsafe.sh