HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICLowContained
Boyd Gaming Corporation
bd_d00c1c2465555cb6 · schema v1 · pii pii-v1
Full breach record for Boyd Gaming Corporation →Boyd Gaming Corporation notified the California Attorney General of a cyber incident involving unauthorized removal of personal information (names and other data elements) from its systems. The unauthorized activity occurred between September 5 and September 7, 2025, and was discovered on September 6, 2025. The company engaged external cybersecurity experts and coordinated with federal law enforcement. Affected individuals were offered two years of complimentary credit monitoring.
California clockDiscovered Sep 6, 2025 → Notified Sep 24, 202518d ✓ CA 60-day OK25 days discovery → filing
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_5466f54815e13dc0Maine State AGfiled 2025-10-01Verified
- bd_4d481001b07bc0f1Vermont State AGfiled 2025-10-02(1d gap)Verified
- bd_5385549096954c1eTexas State AGfiled 2025-10-02(1d gap)Verified
- bd_fa49a9bb13c2a59cIowa State AGfiled 2025-10-02(1d gap)Verified
Show 4 more filings ↓Show fewer ↑up to 8d gap
- bd_08fb36c9e929cb42New Hampshire State AGfiled 2025-10-06(5d gap)Verified
- bd_106fff4bfd61efe6Indiana State AGfiled 2025-09-24(7d gap)Verified
- bd_b508b0707b18975fMontana State AGfiled 2025-09-24(7d gap)Verified
- bd_1a7e1ea1df6ca8ffSEC 8-Kfiled 2025-09-23(8d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-612086
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 1, 2025
- Raw hash
- 98cdf58f35e8bc1b82531e3285d9be9c170020a24a0250e317587dd6e15ce29e
Reporting entity
- Name
- Boyd Gaming Corporationnorm: boyd gaming
Victim entity
- Name
- Boyd Gaming Corporationnorm: boyd gaming
Incident
- Discovered
- Sep 6, 2025
- Materiality determined
- —
- Notification sent
- Sep 24, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Coordinated with federal law enforcement
Compliance
- Time to disclose
- 25 days(25 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 18d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 6, 2025→ Notified: Sep 24, 202518d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.