Boyd Gaming Corporation
ent_019e1f5231257e450b1ef0f8b5a197ee
Disclosures
10
State AG · SEC 8-K · 10 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
11,000
as filed · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Boyd Gaming Corporation
- Normalized
- boyd gaming— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 254900787YGRYS2A1Z35
- SEC EDGAR CIK
- 0000906553
- Domain
- None on record
Disclosure history (10)newest first
- New Hampshire State AGas victim2025-10-06
Boyd Gaming Corporation reported a cyber incident to the New Hampshire Attorney General. Unauthorized access occurred Sept 5-7, 2025, resulting in the exfiltration of personal information (names, addresses, DOB, driver's license, SSN) of 40 NH residents. Boyd discovered the incident on Sept 6, 2025, and notified affected individuals on Sept 24, 2025. Remediation included password resets and enhanced security controls.
- Vermont State AGas victim2025-10-02
Boyd Gaming Corporation notified Vermont AG of a cyber incident involving unauthorized removal of personal information (names) from its systems. The incident occurred between September 5-7, 2025. The company engaged external cybersecurity experts and federal law enforcement, terminated unauthorized access, and offered two years of complimentary credit monitoring. 16 Rhode Island residents were confirmed affected.
- Texas State AGas victim2025-10-02
Boyd Gaming Corporation based in Las Vegas, Nevada, a business – retail or merchant entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-09-06 and reported on 2025-10-02. 4,300 Texas residents were affected. Types of information involved: Name of individual;Address;Social Security Number Information;Driver’s License number;Government-issued ID number (e.g. passport, state ID card);Date of Birth. Consumers were notified via U.S. Mail.
- Iowa State AGas victim2025-10-02
Boyd Gaming Corporation notified the Iowa AG of a cyber incident where unauthorized actors accessed systems between Sept 5-7, 2025. The breach exposed Iowa residents' PII including names, SSNs, and driver's license info. Boyd discovered the incident on Sept 6, 2025, and notified ~4,000 Iowa residents on Sept 24, 2025. Response included engaging forensic experts, resetting passwords, and offering 2 years of credit monitoring.
- Maine State AGas victim2025-10-01
Boyd Gaming Corporation reported a cyber incident in Maine where unauthorized actors accessed systems between Sept 5-7, 2025. Discovered Sept 6, 2025. Personal info of 25 Maine residents, including names, SSNs, and driver's licenses, was exfiltrated. Notifications sent Sept 24, 2025, offering 2 years of identity protection.
- Illinois State AGas victim2025-10-01
BOYD GAMING CORPORATION filed a data-breach notice with the Illinois Attorney General in October 2025 (case 25-10-493). The register records the breach as discovered on September 6, 2025. Personal information types reported: drivers license, passport number, ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- California State AGas victim2025-10-01
Boyd Gaming Corporation notified the California Attorney General of a cyber incident involving unauthorized removal of personal information (names and other data elements) from its systems. The unauthorized activity occurred between September 5 and September 7, 2025, and was discovered on September 6, 2025. The company engaged external cybersecurity experts and coordinated with federal law enforcement. Affected individuals were offered two years of complimentary credit monitoring.
- Indiana State AGas victim2025-09-24
Boyd Gaming Corporation reported a data breach to the Indiana Attorney General. The breach occurred on 2025-09-05 and was reported on 2025-09-24. 11,000 Indiana residents were affected.
- Montana State AGas victim2025-09-24
Boyd Gaming Corporation notified affected individuals of a data breach where unauthorized access occurred between September 5 and 7, 2025. Personal information, including names, was removed from systems. The company engaged external cybersecurity experts and federal law enforcement, terminated access, and offered two years of complimentary credit monitoring and identity protection services.
- FEDERALSEC 8-Kas victim2025-09-23
Boyd Gaming Corporation filed an 8-K on September 23, 2025, disclosing a cybersecurity incident where an unauthorized third party accessed internal IT systems and exfiltrated employee and limited other individual data. The incident had no impact on business operations. The Company engaged external cybersecurity experts and federal law enforcement, and is notifying impacted individuals and regulators.