Former Boyd Gaming employee sues company over data breach
Table of contents
- Former Boyd Gaming employee has filed a class-action lawsuit against the company over a cyberattack that compromised employee and customer data
- The lawsuit claims Boyd’s cybersecurity systems were “completely inadequate” and failed to prevent the theft of Social Security numbers and personal information
- Boyd Gaming disclosed the breach in an SEC filing on 23 September but has not revealed when the attack occurred or whether ransom was paid
Scott Levy, a former Boyd Gaming employee from Las Vegas, has filed a lawsuit against the casino operator following a cyberattack that resulted in the theft of personal information belonging to employees and customers.
The complaint, filed in the US District Court for the District of Nevada last week, seeks class-action status and accuses the company of failing to adequately protect sensitive data.
The lawsuit centres on a cybersecurity incident that Boyd Gaming disclosed in a Securities and Exchange Commission filing on 23 September. The company confirmed that an unauthorised third party accessed its internal IT systems and removed data, including information about employees and a limited number of other individuals.
Inadequate security measures
According to the legal complaint, the stolen information includes Social Security numbers of both current and former employees, as well as company customers. Levy’s legal team stated in the filing that Boyd Gaming had employed “leading external cybersecurity experts” and determined that “the unauthorized third party removed certain data from defendant’s IT systems, including information about employees and a limited number of other individuals”.
“Thus, defendant admitted that personally identifiable information was actually stolen during the data breach, confessing that the information was not just accessed, but was ‘removed’ from Boyd’s system,” the lawsuit states. The plaintiff argues that Boyd Gaming’s cyber and data security systems were “completely inadequate” and allowed cybercriminals to access highly private information.
The legal action accuses Boyd Gaming of negligence, breach of implied contract, unjust enrichment, and violation of the Nevada Consumer Fraud Act. Levy claims the company failed to act in good faith by not revealing when the attack first occurred or whether it paid ransomware to regain control of its systems.
No official statement yet
Boyd Gaming has remained tight-lipped about specific details of the attack, including the timing and scope of the breach. The company stated in its SEC filing that it worked with external cybersecurity experts and notified law enforcement but has declined to comment on pending litigation.
The Las Vegas-based casino operator, which employs over 16,000 people across 28 gaming properties in ten states, has said the incident had no impact on its operations. The company maintains comprehensive cybersecurity insurance coverage, which it expects will cover costs associated with incident response, forensic investigations, business interruptions, legal actions, and regulatory fines.
Boyd Gaming has offered free identity theft protection and credit monitoring for everyone impacted by the breach. The company’s share price has been negatively affected since news of the attack emerged.
This latest incident adds to a growing list of cyberattacks targeting the gaming industry. MGM Resorts International faced a major ransomware attack in September 2023 that caused over $100 million in EBITDA impact and left casino systems offline for days. Caesars Entertainment reportedly paid $15 million to release its systems following a similar attack.
Do you have a story worth sharing?
Send it over to our editors!