In the face of growing concerns about cyber threats in the international business community, MGM Resorts (“MGM”) has confirmed a severe cyber-attack on its systems. The attack, which occurred on Sunday, September 10, 2023, required the corporation to halt operations at multiple Las Vegas hotels.
As reported by Console and Associates, P.C. on JD Supra, the specifics of the attack remain undisclosed as the case is still under investigation. The primary concern for stakeholders and legal professionals, however, revolves around potential data breaches that may have enabled unauthorized access to confidential employee and customer information.
Data breaches, especially in high-profile corporations, pose significant legal and reputational risks. Depending on the nature and extent of the breach, MGM could face substantial penalties under various data protection laws, such as GDPR (General Data Protection Regulation) in Europe, and similar laws in the United States, including California’s CCPA (California Consumer Privacy Act). Beyond regulatory penalties, organizations must also consider the potential for civil litigation such as data breach class actions.
- Under GDPR, companies can be fined up to 4% of their annual global turnover for severe data violations.
- The CCPA allows Californian customers to seek statutory damages ranging from $100 to $750 per incident or actual damages, whichever is greater, in the event of a data breach.
Protecting client and employee data from cyber threats is not just good business practice, but a pressing legal obligation for companies worldwide. Cybersecurity planning and protocols, appropriate data governance, and effective response techniques are essential for mitigating the legal risk associated with data breaches. Law firms and legal teams play a crucial role in these challenging aspects. This latest cyber attack against MGM underscores the critical importance of robust security measures within an increasingly digital and interconnected global economy.