Did Boyd Gaming pay ransom in cyberattack? Company refuses to disclose information

Boyd Gaming Corp. has chosen to remain silent regarding any ransom payments made to cybercriminals who infiltrated its internal IT systems. The Las Vegas-based casino operator, overseeing 11 local properties, disclosed the cyberattack in an official filing with the Securities and Exchange Commission (SEC) without revealing specific details about when the breach occurred or how it was detected.

In response to inquiries, the company refrained from providing additional comments beyond what was mentioned in the SEC filing. They stated that upon detecting the incident, prompt actions were taken with the aid of external cybersecurity experts and federal law enforcement agencies.

In contrast to Boyd Gaming’s discreet approach, other casino enterprises have handled similar cyberattacks differently. In a notable case from 2023, Caesars Entertainment Inc., based in Reno, reportedly paid a staggering $15 million ransom following a system breach, whereas MGM Resorts International declined to comply with ransom demands after a security breach targeted them. Consequently, MGM encountered downtime for nine days, impacting numerous clientele, with an estimated financial cost of $100 million.

While Caesars Entertainment and MGM Resorts International each faced unique consequences following cyber incidents, Boyd Gaming anticipates minimal financial implications resulting from the recent breach. The company asserted that the cybersecurity insurance policy in place would cover various costs associated with incident response, forensic investigations, business interruptions, legal matters, fines, and penalties, subject to policy terms and conditions.

Unlike MGM, who attributed their system compromise to social engineering tactics involving employee manipulation, Boyd Gaming has refrained from detailing the suspected methods utilized by cybercriminals to gain unauthorized access.

The uncertainty surrounding the specifics of the cyberattack against Boyd Gaming leaves room for ongoing developments in this unfolding narrative. The scope and repercussions of the breach remain subject to further updates as the investigation progresses.

For further inquiries or updates on this developing story, please reach out to Richard N. Velotta at [email protected] or dial 702-477-3893. You can also follow @RickVelotta for additional updates.