
Boyd Gaming has been hit with a proposed class action lawsuit following a cybersecurity incident that compromised personal information of current and former employees.
The lawsuit, filed on 25 September in the Nevada District Court by former employee Scott Levy, alleges the regional casino operator failed to implement adequate cybersecurity measures to protect sensitive personally identifiable information.
Boyd Gaming, which operates 28 gaming properties across ten US states, disclosed the breach in a Form 8-K filing with the Securities and Exchange Commission on 23 September.
According to the filing, an unauthorised third party accessed the company’s internal IT system and removed data, including information about employees and a limited number of other individuals.
The complaint said: “Following an investigation into the Data Breach ‘with leading external cybersecurity experts’, Defendant learned cybercriminals gained unauthorized access to current and former employees and customers’ personally identifiable information, including, on information and belief, their name and Social Security number.”
Boyd alleged security failings
Levy, who worked for Boyd Gaming from April 2022 to May 2024, claims the company failed to notify affected individuals promptly about the breach and did not provide sufficient details about its scope or impact.
The complaint alleges Boyd Gaming’s security measures were inadequate despite the company being aware that the casino industry is a frequent target of cyberattacks.
The lawsuit references Federal Bureau of Investigation warnings from November 2023 about ransomware actors exploiting vulnerabilities in vendor-controlled remote access to casino servers, following high-profile ransomware attacks on casino and hotel companies in September 2023.
The complaint adds: “Defendant’s failure to timely report the Data Breach made the victims vulnerable to identity theft without any warnings to monitor their financial accounts or credit reports to prevent unauthorized use of their PII.”
Levy alleges he has experienced a spike in spam and phishing communications since the breach, receiving three to four such texts or phone calls daily.
The lawsuit seeks certification as a nationwide class action on behalf of all US residents whose personal information was accessed or acquired in the breach.
The complaint brings five counts against Boyd Gaming, including negligence, breach of implied contract, unjust enrichment and violation of Nevada’s Consumer Fraud Act.