Days after a class action lawsuit was filed against Wynn Resorts Limited, the casino operator has confirmed that a cybersecurity incident led to unauthorised access to employee data, while contesting claims in a federal class action lawsuit that the breach affected customer records.
The development follows a lawsuit filed in Nevada under the case Reed v. Wynn Resorts Limited, which claims that hacking group ShinyHunters stole the personal information of more than 800,000 customers. Wynn has now stated that the incident involved employee data only and had no impact on guests or operations.
Wynn confirms employee data breach
As per a report by news agency Reuters, Wynn’s chief communications officer Michael Weaver said in an email on Tuesday that the company had learned that “an unauthorised third party acquired certain employee data,” and that it immediately launched an investigation with external cybersecurity experts.
“The unauthorised third party has stated that the stolen data has been deleted,” Weaver said. “We are monitoring and to date have not seen any evidence that the data has been published or otherwise misused.”
Weaver added that the incident “has had no impact on our guest experience, our operations or our physical properties, which are all fully operational and open for business.”
A separate statement described the breach as a cybersecurity incident in which a third party accessed employee data. Wynn said the incident did not impact customers or day-to-day operations.
Wynn did not disclose how many employees were affected. Weaver also declined to answer questions about whether any money was paid to the hackers.
A representative of the hacking group told Reuters in an online chat that they were demanding 22.34 bitcoin, worth roughly $1.5 million. The representative would not comment on any payment but said the data had been deleted.
Lawsuit alleges customer data exposure
The company’s statement directly challenges the allegations set out in the class action complaint. The lawsuit, filed on 21 February in the US District Court for Nevada, claims that ShinyHunters stole more than 800,000 digital records of Wynn customers. It states that the data included social security numbers and other personal details.
Plaintiff Richard Reed, identified as a California man and current or former customer, alleges that Wynn’s improper handling of customers’ sensitive personal information led to the breach.
The complaint states, “On 20 February 2026, the notorious hacking group ShinyHunters announced it had stolen over 800,000 records from Defendant containing the personal information of Plaintiff and Class Members.”
It continues, “By obtaining, collecting, using, and deriving a benefit from the Private Information of Plaintiff and Class Members, Defendant assumed legal and equitable duties to those individuals to protect and safeguard that information from unauthorised access and intrusion.”
The filing argues that Wynn failed to protect “highly sensitive” personal information and left data unencrypted and unredacted.
“Defendant failed to adequately protect Plaintiff’s and Class Members’ Private Information and failed to even encrypt or redact this highly sensitive information. This unencrypted, unredacted Private Information was compromised due to Defendant’s negligent and or careless acts and omissions and its utter failure to protect Plaintiff’s and Class Members’ sensitive data. Hackers targeted and obtained Plaintiff’s and Class Members’ Private Information because of its value in exploiting and stealing the identities of Plaintiff and Class Members. The present and continuing risk of identity theft and fraud to victims of the Data Breach will remain for their respective lifetimes.”
According to the lawsuit, the compromised information may include names, email addresses, contact details and potential account-related data.
However, Wynn’s statement to media outlets indicates that the data accessed related to current and former employees, not customers.

Notification and response questioned
The lawsuit also criticises Wynn’s communication with those affected. It states that the company’s Notice Letter failed to provide full details of the incident.
“Omitted from the Notice Letter were the identity of the cybercriminals who perpetrated this Data Breach, the details of the root cause of the Data Breach, the vulnerabilities exploited, and the remedial measures undertaken to ensure such a breach does not occur again. To date, these critical facts have not been explained or clarified to Plaintiff and Class Members, who retain a vested interest in ensuring that their Private Information remains protected.”
Reed argues that the disclosure amounted to no “real” disclosure of critical facts and that affected individuals’ ability to mitigate harm was “severely diminished.”
The complaint calls for a jury trial and damages, along with class certification, injunctive relief, attorneys’ fees and other remedies.
Wynn has said that, while the investigation is ongoing, it has elected to offer complimentary credit monitoring and identity protection to all employees.
“While the investigation is ongoing, we have elected to offer complimentary credit monitoring and identity protection to all employees,” Weaver said. “The security and confidentiality of our employees, as well as our guest data, is our top priority. While no company can ever eliminate the risk of a cyberattack, we are taking appropriate steps and working with industry leading third party IT advisors to strengthen our systems to protect against future incidents.”
SEC disclosure and cyber risk
In a December 2024 Securities and Exchange Commission filing, Wynn acknowledged that it faces cybersecurity risks.
“Despite the security measures we currently have in place, our facilities and systems and those of our third-party information system service providers may be vulnerable to security breaches, acts of vandalism, phishing attacks, computer viruses, worms, ransomware, malicious software programs, misplaced or lost data, programming or human errors and other events,” the filing said.
“Cyber attacks are becoming increasingly more difficult to anticipate, prevent and detect due to their rapidly evolving nature and, as a result, the technology we use to protect our systems from being breached or compromised could become outdated due to advances in computer capabilities or other technological developments.”
The lawsuit alleges that Wynn knew or should have known about basic cybersecurity risks in today’s environment, particularly after high-profile incidents involving Caesars Entertainment and MGM Resorts.
Industry context and past cases
The Wynn case comes after similar cyber incidents at other major resort companies. In September 2023, MGM Resorts International was affected by a cyberattack that disrupted operations at its Las Vegas properties. In January 2025, MGM agreed to a $45 million settlement linked to its 2019 and 2023 data breaches.
In the same month in 2023, Caesars Entertainment confirmed that hackers had accessed its loyalty programme database and said it paid about $15 million to the attackers. In 2023, Marina Bay Sands in Singapore also reported that around 665,000 rewards members were affected by a data incident.
These cases show that large resort operators remain attractive targets due to the volume of employee and customer data they manage.
What happens next
Wynn Resorts comprises five properties, including in Las Vegas, Boston and Macau, and employs more than 28,000 people. The company generates approximately $1.87 billion in revenue.
The Reed v. Wynn Resorts Limited case will now proceed through federal court in Nevada. Wynn has not admitted wrongdoing and has indicated that the breach involved employee data only. It remains unclear whether any ransom was paid or whether the alleged 800,000 records cited in the lawsuit relate to employees, customers or a combination of both.
For now, Wynn says its operations remain unaffected and that its properties are fully open for business. The legal dispute will determine whether the court accepts the plaintiff’s claim that customer data was exposed or Wynn’s position that the incident was limited to employee information.
A new frontier rises beneath the skyline of São Paulo. From 06–09 April 2026, BiS SiGMA South America transforms LatAm’s gaming capital into a hub of innovation, bold talks, and billion-dollar opportunity. Don’t sit this one out.