Legal
Rivers Casino Philadelphia May Have Failed to Protect Employee and Patron Information
Posted on: August 11, 2026, 09:05h.
Last updated on: August 11, 2026, 09:05h.
Rivers Casino Philadelphia admitted to a data breach in November 2024 that exposed employees’ personal information to the dark web. The casino was subsequently sued on a series of allegations, some of which a federal judge says have merit to proceed.

Chicago-based Rush Street Gaming, the parent company of Rivers Philadelphia, asked Judge Joshua Wolson of the US District Court for the Eastern District of Pennsylvania in March to dismiss the proposed class-action lawsuit. The plaintiffs argued that Rivers Casino, as a business entrusted with sensitive personal information, failed in its duty to protect that data.
Wolson agreed that several of the plaintiffs’ allegations lacked merit but found that their primary negligence claim had sufficient grounds to proceed.
“Plaintiffs have plausibly alleged that Rivers failed to exercise reasonable care in safeguarding their personal information,” Wolson concluded in his 21-page memorandum.
Employees Possibly Impacted
Rivers Casino Philadelphia first acknowledged the data breach in January 2025. At the time, the casino believed that information only on employees was stolen.
“We regret any inconvenience or concern this incident may cause you. Rivers Casino Philadelphia recognizes the importance of protecting the personal information we maintain,” a letter from the casino to employees read.
The casino offered workers one year of free credit monitoring. The lawsuit claims that patrons were also impacted.
The hackers reportedly stole more than 2.56 terabytes of data, later posting the information for sale on the dark web. The stolen material included Social Security and driver’s license numbers, passport details, and banking information.
2.56 terabytes of data is capable of holding around 17 million PDF pages of mixed documents (text and images). On an organizational basis, 2.56 terabytes isn’t an overly large data trove, as even medium-sized companies like Rivers Casino Philadelphia routinely store more than a petabyte (1,000 TB) of data.
Several plaintiffs alleged in the lawsuit that they’ve experienced the attempted misuse of their information, including credit card inquiries, fraudulent changes, and phishing communications.
Plaintiff Mark Metzler alleged that there were unauthorized Peacock subscription charges on his Wells Fargo credit card. Plaintiff Shawn Martin claimed he experienced a “substantial increase” in spam calls, emails, and text messages following the cyber incident.
Rivers Arguments
Attorneys for Rivers Casino Philadelphia argued in their motion to dismiss that phishing emails, spam, random texts, suspicious logins, and fraudulent charges are common occurrences that could have stemmed from any number of unrelated incidents.
Wolson disagreed, saying the evidence could prove a direct link to the casino data compromise. However, the judge sided with Rivers in dismissing the complaint’s other claims, including breach of implied contract, breach of fiduciary duty, invasion of privacy, and unjust enrichment.
Rivers is now given time to respond to the surviving claims before a court schedule is established.
Conversation (0)
Be the first to comment on this article.