Is BetMGM safe? Split the question in two and the answer changes. Ask about licensing, payouts, and account-level controls, and yes — this is a state-regulated operator with geolocation that actually works and responsible-gambling tools that follow a player across state lines. Ask about data security specifically, and the record includes a real breach that exposed personal information on roughly 1.5 million people. Both are true. Neither cancels the other out.

Licensing Safety: The Part That Checks Out

BetMGM holds individual sportsbook licenses in 23 states plus Washington D.C. as of September 2026, each one issued and audited by that state's own gaming regulator. Geolocation software confirms a bettor is physically inside a licensed state before a wager is accepted — it is the mechanism that makes "legal in my state" an enforceable fact rather than a marketing line. That infrastructure is the same across every state-licensed operator this site reviews, and BetMGM meets it.

The 2022 Breach BetMGM Disclosed

BetMGM discovered a data security incident in November 2022 that it later determined had occurred the previous May. The exposed data included names, contact information, dates of birth, hashed Social Security numbers, account identifiers, and transaction-related information, affecting an estimated 1.5 million current and former customers. Class-action filings allege some of that information sat in an unencrypted, internet-accessible database — a claim distinct from what was taken, and one BetMGM has faced in litigation rather than conceded outright.

What BetMGM says wasn't touched: the company has stated it found no evidence that account passwords or funds were accessed, and that its online betting operations continued running without disruption through the incident.

A Separate, Bigger Incident: MGM Resorts, September 2023

A year later, majority co-owner MGM Resorts was hit by its own cyberattack that forced a shutdown of casino-floor systems across its properties and cost roughly $100 million in adjusted earnings. Criminal actors obtained data including driver's license numbers and, for a limited number of customers, Social Security and passport numbers. BetMGM's online sportsbook was widely reported as largely unaffected by this second, larger incident — the outage was concentrated in MGM's physical casino systems and some BetMGM-branded kiosks on property, not the mobile app itself.

The Account Tools That Are Actually Real

Separate from the breach history, BetMGM's in-app safety tools are genuine and consolidated: deposit, loss, and session limits set in the Responsible Gaming menu, time-outs, and self-exclusion built on GameSense, the program MGM Resorts licenses and has used to certify more than 3,000 staff as GameSense Advisors since integrating it into the app in 2022. A restriction set in one state follows the account into every other state BetMGM operates in.

What to Actually Do With This

  • Use a password unique to BetMGM, not one reused from another account — the single highest-value step after any breach disclosure, regardless of brand.
  • Treat identity-verification requests inside the official app as normal; treat unsolicited emails or texts referencing either incident asking you to "re-verify" by clicking a link as phishing.
  • Set a deposit or session limit through GameSense tools if you haven't already — unrelated to the breach, but the actual safety feature most players never turn on.

Licensed and regulator-accountable: yes. A perfect data-security record: no. Both facts belong in the same answer. Treat any deposit as entertainment spend, not income. 21+ where legal. 1-800-GAMBLER.