Rivers Casino faces growing legal challenges following massive data breach

Rivers Casino Philadelphia, operated by Rush Street Gaming, is under intense legal scrutiny following a significant data breach that exposed the sensitive personal and financial information of employees and customers.

The data breach, initially identified in late November 2024, has already led to at least three lawsuits, including a class-action complaint filed in federal court.

The intrusion has drawn attention to the casino’s cybersecurity practices and sparked broader concerns about the handling of private data in the gaming industry.

The incident came to light when Rivers Casino filed a notice with the Massachusetts Attorney General on December 30, 2024, detailing the breach.

According to the notice, an unauthorised party accessed the company’s computer servers, stealing files containing names, Social Security numbers, and bank account details. Both employees and customers were affected.

The casino, in letters to affected individuals, acknowledged that the compromised data included sensitive information used for direct deposit, raising fears of identity theft and financial fraud.

Investigations and legal actions begin

In response to the breach, Rivers Casino launched an internal investigation and began notifying impacted parties in late December. The company also offered free credit monitoring services to those affected.

However, critics argue that the response was both inadequate and delayed. Some affected individuals have reported a surge in phishing emails and fraudulent activities linked to their compromised information.

Two prominent class action law firms, Levi & Korsinsky, LLP, and Edelson Lechtzin LLP, have launched investigations into the breach, focusing on whether Rivers Casino violated data privacy laws or failed to implement adequate cybersecurity measures.

Both firms are evaluating potential claims on behalf of affected individuals, with the companies providing online portals for victims to check their eligibility for compensation.

Adding to the legal challenges, a lawsuit requesting class-action status has been filed in the US District Court for the Eastern District of Pennsylvania by plaintiff Kevin Brady on behalf of those impacted.

The complaint alleges negligence, failure to adhere to accepted data security standards, and delayed notification of the breach.

Brady claims that the casino’s failure to secure sensitive data has caused direct harm, including financial losses and significant time spent mitigating potential identity theft.

Gaming industry remains at risk

The breach has far-reaching implications for both individuals and the gaming industry. Rivers Casino operates in multiple states, meaning the impact may extend beyond Philadelphia.

Rush Street Gaming has asserted that this isn’t the case.

Data breaches in the gaming sector have become an escalating concern, with hackers targeting companies that store extensive financial data.

Notably, MGM Resorts and Caesars suffered massive attacks two years ago that are still causing legal disputes.

Personal information, such as Social Security numbers and bank account details, is highly valuable to cybercriminals and can be exploited for long-term fraud.

According to industry reports, data breaches of this nature expose victims to heightened risks for years, as replacing compromised Social Security numbers is particularly challenging.

In some instances, a full recovery from the personal data compromise has been impossible for some individuals.