Former Boyd Gaming employee sues after cybersecurity breach disclosed

A lawsuit has been filed by a former Boyd Gaming employee against the company following the disclosure of a cybersecurity incident. The incident was revealed in an SEC filing by Boyd officials, stating that an unauthorized third party had accessed their internal IT system. Although the company assured that their properties and business operations were unaffected, the third party did manage to obtain information about employees and a limited number of individuals.

The company mentioned that they would notify the impacted individuals and relevant regulators as necessary. In response to this disclosure, Scott Levy, a former Boyd Gaming employee, filed a class action lawsuit against the company. Levy expressed concerns about the lack of clarity regarding when the hackers infiltrated the system and how long they had access to employee information. The lawsuit highlights the inadequacy of Boyd’s cyber and data security systems, emphasizing that the breach exposed employees’ and customers’ private information to potential theft and sale on the dark web. Levy also noted an increase in spam and phishing attempts since the data breach, claiming that Boyd Gaming failed to notify him or other employees of the exposure of their information.

As of Monday morning, no court hearings had been scheduled concerning this matter. Despite the absence of detailed information, John Branden Newman, the Chief Technology Officer for MGM Resorts International, stated that his team offered assistance to Boyd Gaming in light of the cyber incident. The ongoing cyberattacks in the region have raised concerns, with Governor Joe Lombardo confirming that nearly all State of Nevada websites are operational again after a cyberattack led to systems being offline for three weeks.

Recently, a teenager was arrested in Las Vegas for involvement in cyberattacks against MGM Resorts International and Caesars Entertainment in 2023. Las Vegas police described these attacks as sophisticated network intrusions, attributing them to an organized threat-actor group under various names, including Scattered Spider and Octo Tempest. The Clark County District Attorney’s Office may consider transferring the case to the criminal division, possibly leading to adult charges.

The lawsuit filed by the former Boyd Gaming employee sheds light on the increasingly prevalent issue of cybersecurity threats. While companies like Boyd Gaming face challenges in safeguarding sensitive information, the consequences of breaches can have far-reaching impacts on employees and customers. The incident serves as a reminder of the critical need for robust cybersecurity measures and proactive responses to mitigate risks in the ever-evolving digital landscape.