DisclosureLens
HackingRetail & ConsumerRetailStolen CredentialsData ExfiltratedCustomer Data InvolvedIdentity (basic)Government IDMediumContained

Boyd Gaming Corporation

bd_08fb36c9e929cb42 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Sep 6, 2025

Filed

Oct 6, 2025

To disclose

4 weeks

Affected

40state residents only

Linked

10 filings

Confidence

66%
Full breach record for Boyd Gaming Corporation

Boyd Gaming Corporation reported a cyber incident to the New Hampshire Attorney General. Unauthorized access occurred Sept 5-7, 2025, resulting in the exfiltration of personal information (names, addresses, DOB, driver's license, SSN) of 40 NH residents. Boyd discovered the incident on Sept 6, 2025, and notified affected individuals on Sept 24, 2025. Remediation included password resets and enhanced security controls.

Incident timeline

undetected · 1 days
discovery → filing · 4 weeks / 30 days

Sep 5, 2025

Begins

Sep 6, 2025

Discovered

Oct 6, 2025

Filed

vs. sector median

4 wks faster

This filing is one of 10 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (9) · sorted by filing gap

Show 5 more filingsup to 13d gap

Filing propagation · 10 filings · 9 states

View merged incident ↗

Pattern: first filing Sep 23, last Oct 6 (NH) — a 13-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.