HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Boyd Gaming Corporation
bd_08fb36c9e929cb42 · schema v1 · pii pii-v1
Full breach record for Boyd Gaming Corporation →Boyd Gaming Corporation reported a cyber incident to the New Hampshire Attorney General. Unauthorized access occurred Sept 5-7, 2025, resulting in the exfiltration of personal information (names, addresses, DOB, driver's license, SSN) of 40 NH residents. Boyd discovered the incident on Sept 6, 2025, and notified affected individuals on Sept 24, 2025. Remediation included password resets and enhanced security controls.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_4d481001b07bc0f1Vermont State AGfiled 2025-10-02(4d gap)Verified
- bd_5385549096954c1eTexas State AGfiled 2025-10-02(4d gap)Verified
- bd_fa49a9bb13c2a59cIowa State AGfiled 2025-10-02(4d gap)Verified
- bd_5466f54815e13dc0Maine State AGfiled 2025-10-01(5d gap)Verified
Show 4 more filings ↓Show fewer ↑up to 13d gap
- bd_d00c1c2465555cb6California State AGfiled 2025-10-01(5d gap)Verified
- bd_106fff4bfd61efe6Indiana State AGfiled 2025-09-24(12d gap)Verified
- bd_b508b0707b18975fMontana State AGfiled 2025-09-24(12d gap)Verified
- bd_1a7e1ea1df6ca8ffSEC 8-Kfiled 2025-09-23(13d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/boyd-gaming-20251006.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 6, 2025
- Raw hash
- 45a965e44e4ac42051b1067da54332b12ae22c4d3451db3c32556ba4baa5ff3f
Reporting entity
- Name
- Morrison & Foerster LLPnorm: morrison foerster
Victim entity
- Name
- Boyd Gaming Corporationnorm: boyd gaming
Incident
- Discovered
- Sep 6, 2025
- Materiality determined
- —
- Notification sent
- Sep 24, 2025
- Affected individuals
- 40
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Coordinated with federal law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.