2026 Wynn Resorts — confirmed employee data theft; ~800K records (ShinyHunters)
Data compromised
Names, SSNs, dates of birth, emails, phone numbers, salaries
Technical writeup
Verified company confirmation — February 2026. Las Vegas casino/hotel operator Wynn Resorts told SecurityWeek and other outlets that an unauthorized third party acquired certain employee data after ShinyHunters listed the company on its leak site (~800,000 records claimed, including PII/SSNs and employee data). Wynn said guest operations were unaffected, activated incident response with external experts, and offered credit monitoring/identity protection to affected employees. The Register reported a ~22.34 BTC (~$1.5M) ransom demand; Wynn said the actor claimed stolen data was deleted and Wynn had not seen evidence of publication or misuse; it declined to confirm whether a ransom was paid. Trade press linked access to a September 2025 Oracle PeopleSoft path using stolen credentials. Catalog count 800000 reflects the widely reported ShinyHunters/employee-record figure; California AG also lists a related Wynn Resorts, Limited notice (Apr 3, 2026).
Root cause
Oracle PeopleSoft vulnerability; stolen employee credentials