Skip to main content
All Watch files
ConfirmedAML & integrity·Watch Explained·Pennsylvania, United States·KYC and account fraud

BetMGM fined $100,000 after four fraud rings opened 2,024 betting accounts

Pennsylvania's regulator says weak KYC controls let fraud rings use other people's identities and stolen or fraudulently obtained payment devices.

Published 26 August 2026 · Updated 26 August 20267 minute read
By iGaming Atlas Editorial Team1 primary sourcesNext review 2 September 2026
Jump to a section

Evidence behind the story

What we checked

Primary documents

1 checked

Response record

Response included

Last source check

26 August 2026

Next scheduled review

2 September 2026

Why this matters

KYC is often discussed as an onboarding checkbox. This case shows the operational consequence of weak controls over time: repeated account creation, cross-account access and fraudulent payment use across two wagering brands.

Procedural status

Consent agreement approved

The Pennsylvania Gaming Control Board approved the enforcement settlement at its 25 March 2026 public meeting. The public release describes a completed $100,000 regulatory fine.

The current picture

  • The Pennsylvania Gaming Control Board approved a consent agreement resulting in a $100,000 BetMGM fine on 25 March 2026.
  • The regulator identified four fraud rings that collectively created 2,024 accounts on the BetMGM and Borgata platforms.
  • Adding the wagering figures disclosed for the four rings produces more than $2.007 million, but that is account wagering, not a regulator-stated loss figure.

Confirmed by the record

  • The fraud rings used personal identifying information belonging to other people.
  • The accounts were funded with stolen or fraudulently obtained payment devices, according to the consent-agreement summary.
  • The four disclosed operating periods ranged from approximately 19 to 34 months.
  • The full approved consent agreement is available from the regulator on request rather than linked in the public release.

Not established

  • The release does not say BetMGM employees stole identities or operated the fraud rings.
  • The disclosed wagering amount is not the same as operator revenue, victim loss, illicit proceeds or money withdrawn.
  • The public summary does not identify the people behind the rings or state the outcome of any related criminal case.
  • The $100,000 regulatory fine should not be added to the wagering total as though both figures measure the same thing.

Sources for each key claim

Evidence map

Each core claim is paired with the document used to substantiate it. Open the record and check our reading.

1

The Pennsylvania Gaming Control Board approved a consent agreement resulting in a $100,000 fine to BetMGM.

2

Four fraud rings created 2,024 accounts using personal information belonging to other people.

3

The accounts used stolen or fraudulently obtained payment devices across the BetMGM and Borgata platforms.

4

The published ring-level wagering figures add to more than $2.007 million, with one component reported only as more than $14,598.

What changed, and when

  1. 30 November 2023

    One 119-account ring ends

    The regulator says this ring operated for about 29 months and recorded $895,092 in combined wagering.

  2. 31 December 2023

    The 304-account ring ends

    Its reported 19-month run generated $867,910 in combined wagering.

  3. 31 January 2024

    The largest account cluster ends

    The 1,567-account ring had operated for about 25 months and recorded $229,580 in wagering.

  4. 30 November 2024

    The final disclosed ring ends

    The 34-account group operated for about 34 months and recorded more than $14,598 in wagering.

  5. 25 March 2026

    Board approves the consent agreement

    The PGCB announced the $100,000 fine and the four-ring account data.

Four rings, 2,024 accounts

Pennsylvania's gambling regulator has put unusually specific numbers around a KYC failure. Four fraud rings created a combined 2,024 accounts on BetMGM and Borgata wagering platforms using personal identifying information belonging to other people, according to a consent agreement approved by the Gaming Control Board.

The Board fined BetMGM $100,000. Its public summary says insufficient procedures allowed people to create, access and use multiple accounts, then fund them with stolen or fraudulently obtained payment devices. The enforcement finding is about BetMGM's controls; the release does not accuse its employees of running the schemes.

The wagering total needs a label

The regulator reports $229,580 in wagering for a 1,567-account ring, more than $14,598 for a 34-account ring, $895,092 for a 119-account ring and $867,910 for a 304-account ring. Adding the disclosed figures gives more than $2,007,180.

That calculation is useful only with its units intact. It is combined wagering recorded in the public release. It is not a published estimate of customer losses, operator profit, stolen funds, withdrawals or recoverable victim claims. Turnover can circulate through multiple bets and should not be converted into a damage figure.

The long duration is the sharper signal

The four rings operated for roughly 19, 25, 29 and 34 months. Their account counts and wagering patterns differed dramatically: the largest cluster by accounts had much less wagering than two of the smaller clusters. A control model focused only on account volume or only on spend could therefore miss a different part of the pattern.

KYC does not stop after a document is accepted. Repeated device use, identity reuse, payment ownership, linked accounts and behavioural connections all create later opportunities to detect a network. The Board's finding points to procedures that were not sufficient to prevent the conduct across the two platforms.

What the public record leaves out

The release identifies the rings by statistics, not by names. It does not publish charging documents, victim totals or criminal outcomes. It also does not provide the full remediation schedule or explain which exact control detected each ring in the end.

The full approved consent agreement is available on request through the Board's communications office. That document, rather than speculation about undisclosed cases, is the next source capable of clarifying the agreed findings and remedies.

Why a $100,000 fine can sit beside $2 million in wagering

The two figures answer different questions. The $100,000 is a regulatory penalty agreed in the consent process. The more-than-$2.007-million calculation describes wagering activity attributed to the four rings in the Board's summary. There is no defensible ratio that turns one into a percentage price for the other.

What the case establishes is narrower and more useful: BetMGM's KYC procedures were insufficient to prevent four long-running fraud rings from using other people's identities and compromised payment devices. The scale is visible in accounts, months and wagering, while the human and criminal outcomes remain outside the published record.

What stronger controls would have to connect

A durable response cannot rely on one improved document check. The pattern described by the Board spans identity ownership, account linkage, payment-device ownership and behaviour over time. Controls need to connect those signals while giving legitimate customers a route to resolve false positives and identity-theft consequences.

The public release does not disclose BetMGM's full remediation programme, so this story should not grade measures it cannot see. The consent agreement is the appropriate next document because it may identify undertakings, deadlines or control changes that the press summary leaves out.

A consent agreement is an outcome, not a full case file

Approval at a public Board meeting makes the $100,000 result a completed regulatory action. It does not make the short announcement a complete evidentiary record of every incident. The regulator explicitly says the fuller agreement is available on request.

That is the boundary Atlas will maintain. The ring-level data can support a precise account of scale, but names, victim outcomes and criminal liability need separate primary records before they enter the story.

Response record

The approved consent agreement is BetMGM's negotiated response mechanism. The public release does not reproduce a separate company statement; the article does not infer admissions beyond the Board's summary.

Status: included

Sources checked