Resort and casino giant Wynn is already facing a class-action lawsuit over an alleged data breach that was reported over the weekend.
The notorious hacking group ShinyHunters allegedly stole more than 800,000 sensitive documents from Wynn in a sophisticated hack and is demanding a ransom, according to a report from Cybernews. The hack allegedly took place back in the fall, but it wasn’t until the weekend that news broke about the incident.
ShinyHunters claims the documents include personal and employee information. The hackers are demanding roughly $1.55 million in bitcoin and have threatened to release the information to the public this week if their demands are not met.
It only took one day after news of the hack broke for a class-action lawsuit to be filed in a Nevada Court against Wynn Resorts over the breach. Richard Reed, the representative plaintiff, alleged that Wynn failed to adequately protect his private information by failing to use proper encryption or to redact highly sensitive information.
Keep Reading
Some Doubt on What Hackers Actually Stole From Wynn
Despite the class-action lawsuit, questions remain about what ShinyHunters actually acquired from Wynn.
The cybercrime group has a history of recycling old documentation and exaggerating its claims, according to reports.
On the other hand, U.K. tech publication The Register reportedly received a sample from ShinyHunters that featured employees’ full names, positions, emails, phone numbers, salaries, start dates, birthdays, and other personal information
ShinyHunters told The Register it acquired the data by using an employee’s credentials to exploit a vulnerability in Oracle PeopleSoft software back in September of 2025.
Wynn has yet to make a statement on the alleged ShinyHunters hack. The resort group has until the end of the day to respond to ShinyHunters, after which the hackers have threatened to release all the data to the public.
Wealthy Las Vegas casinos are a ripe target for hackers. Back in 2023, both MGM and Caesars were targeted by the hacking group Scattered Spiders. Interestingly, there are some ties between Scattered Spiders and ShinyHunters, which gives more credence to the alleged Wynn breach.
Plaintiff Alleges He’s Already Been Affected by Hack
Plaintiff Richard Reed claims to have already suffered negative consequences following the alleged September data breach. Most of the complaints revolve around being effectively doxxed by the hack.
According to the filing, the injuries suffered by the plaintiff and class members include:
- Invasion of privacy and theft of private information, resulting in its loss or diminished value.
- Financial losses, including lost time and opportunity costs, were incurred attempting to mitigate the breach consequences.
- Actual misuse of the compromised data, such as an increase in spam communications.
- Continued and increased risk to private information, as it remains unencrypted, backed up in the Defendant’s possession, and subject to further unauthorized disclosures.
The lawsuit seeks damages and a court-ordered overhaul of Wynn’s cybersecurity protocols, including third-party audits over the next decade.






