In November 2024, Rivers Casino Philadelphia reported a data breach that compromised the personal information of its employees, which subsequently appeared on the dark web. Following this incident, the casino faced legal action over several claims, with a federal judge affirming that some of the allegations have enough merit to move forward.

Rush Street Gaming, the parent company of Rivers Casino Philadelphia, sought to have the proposed class-action lawsuit dismissed in March, appealing to Judge Joshua Wolson of the US District Court for the Eastern District of Pennsylvania. The plaintiffs contended that the casino, which holds sensitive personal information, neglected its responsibility to safeguard that data.
While Judge Wolson found several plaintiff allegations lacking in merit, he determined that the main negligence claim had enough foundation to proceed.
Wolson noted in his 21-page memorandum, “The plaintiffs have made plausible claims that Rivers did not take reasonable precautions to protect their personal information.”
Employees Potentially Affected
Rivers Casino Philadelphia initially recognized the data breach in January 2025, believing at that time that only employee information had been compromised.
The casino expressed regret over the incident in a letter to employees, stating, “We understand the importance of safeguarding the personal information we collect and maintain.”
In response, the casino offered its employees a year of complimentary credit monitoring. The lawsuit also alleges that customers may have been affected.
Reports indicate that hackers stole over 2.56 terabytes of sensitive data, later posting this information for sale on the dark web. The breach included Social Security numbers, driver’s license details, passport information, and banking data.
To put that in perspective, 2.56 terabytes can hold approximately 17 million PDF documents (a mix of text and imagery). In terms of organizational data, 2.56 terabytes isn’t excessively large; even mid-sized organizations routinely handle over a petabyte (1,000 TB) of data.
Multiple plaintiffs in the lawsuit claimed they encountered attempts to misuse their information, including unauthorized credit inquiries, fraudulent alterations, and phishing attempts.
Plaintiff Mark Metzler reported that there were unapproved subscription charges on his Wells Fargo credit card. Plaintiff Shawn Martin mentioned a noticeable surge in spam communications, including calls, emails, and texts, following the cyber event.
Arguments from Rivers Casino
Legal representatives for Rivers Casino Philadelphia argued in their motion to dismiss that phishing attempts, spam, random texts, suspicious logins, and fraudulent charges are commonplace issues that might arise from various unrelated incidents.
Judge Wolson countered this view, suggesting that the evidence could indicate a direct correlation to the casino’s data breach. Nevertheless, he sided with Rivers in dismissing other claims within the complaint, including breach of implied contract, breach of fiduciary duty, invasion of privacy, and unjust enrichment.
Rivers Casino is now preparing to respond to the remaining claims as a court schedule is established.

