CIO Brief: Customer Data Leaks and Reputational Damage
Retrospective: this article looks back at events from February 2020, written in 2026 with the benefit of hindsight.
The short version: In 2020, personal details of more than 10 million MGM hotel guests appeared on a hacking forum, from an earlier breach of a cloud server. Even "basic" contact information creates lasting risk for customers and reputational damage for the company.
Why basic data still matters
Names, addresses, phone numbers and birthdates aren't payment cards, but they are the raw material for phishing, fraud and impersonation. Leaked data circulates for years, and customers associate each new scam with your brand.
The business impact
- Reputational harm when data appears publicly, sometimes long after the breach.
- Customer churn, especially among high-value customers.
- Regulatory costs for notification and investigations.
- Social engineering risk against your own help desk using leaked details.
Questions to ask your team
- How many years of customer data do we keep, and why?
- Which cloud systems hold customer data, and who owns each one?
- Would we know if our customer data appeared for sale online?
- Do we verify customers' identities using information that may already be leaked?
What good looks like
A data retention policy actually enforced, an inventory of customer data stores with owners, monitoring for data leaks, and identity verification that doesn't rely on easily obtained personal details.
The decision
Ask for a data retention review of your largest customer database. Deleting data you no longer need reduces breach impact more cheaply than any security tool.
- MGM Resorts Guest Data Leak (Feb 2020): 10 Million Records From a Cloud Server Incident Teardowns
- How to Classify and Monitor Customer Data Stores Across Clouds How-To & Hardening
- Detecting Cloud Server Data Exposure: Sentinel and GuardDuty Detections Detection & Response