Boyd Gaming Corporation
ent_019e1f5231257e450b1ef0f8b5a197ee
Disclosures
10
SEC 10-K Item 1C · State AG · SEC 8-K · 9 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
11,000
as filed · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Boyd Gaming Corporation
- Normalized
- boyd gaming— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 254900787YGRYS2A1Z35
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (10)newest first
- FEDERALSEC 10-K Item 1Cas victim2026-02-20
Boyd Gaming Corporation (Form 10-K, Item 1C) discloses its cybersecurity risk management and governance framework. The filing states that cybersecurity threats have not materially affected the Company's business, results of operations, or financial condition. No specific cybersecurity incident, breach, or material impact is reported.
- ⛰️New Hampshire State AGas victim2025-10-06
Boyd Gaming Corporation reported a cyber incident to the New Hampshire Attorney General. Unauthorized access occurred Sept 5-7, 2025, resulting in the exfiltration of personal information (names, addresses, DOB, driver's license, SSN) of 40 NH residents. Boyd discovered the incident on Sept 6, 2025, and notified affected individuals on Sept 24, 2025. Remediation included password resets and enhanced security controls.
- 🍁Vermont State AGas victim2025-10-02
Boyd Gaming Corporation notified Vermont AG of a cyber incident involving unauthorized removal of personal information (names) from its systems. The incident occurred between September 5-7, 2025. The company engaged external cybersecurity experts and federal law enforcement, terminated unauthorized access, and offered two years of complimentary credit monitoring. 16 Rhode Island residents were confirmed affected.
- ⭐Texas State AGas victim2025-10-02
Boyd Gaming Corporation based in Las Vegas, Nevada, a business – retail or merchant entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-09-06 and reported on 2025-10-02. 4,300 Texas residents were affected. Types of information involved: Name of individual;Address;Social Security Number Information;Driver’s License number;Government-issued ID number (e.g. passport, state ID card);Date of Birth. Consumers were notified via U.S. Mail.
- 🌽Iowa State AGas victim2025-10-02
Boyd Gaming Corporation, a hospitality sector entity reported a data breach to the Iowa Attorney General. The breach was reported on 2025-10-02.
- 🦞Maine State AGas victim2025-10-01
Boyd Gaming Corporation reported a data breach affecting 25 Maine residents, which occurred from September 5 to September 7, 2025. The company discovered the breach on September 6, 2025, and notified affected individuals on September 24, 2025. Identity theft protection services were offered through IDX.
- 🐻California State AGas victim2025-10-01
Boyd Gaming Corporation notified the California Attorney General of a cyber incident involving unauthorized removal of personal information (names and other data elements) from its systems. The unauthorized activity occurred between September 5 and September 7, 2025, and was discovered on September 6, 2025. The company engaged external cybersecurity experts and coordinated with federal law enforcement. Affected individuals were offered two years of complimentary credit monitoring.
- 🏎️Indiana State AGas victim2025-09-24
Boyd Gaming Corporation reported a data breach to the Indiana Attorney General. The breach occurred on 2025-09-05 and was reported on 2025-09-24. 11,000 Indiana residents were affected.
- 🦬Montana State AGas victim2025-09-24
Boyd Gaming Corporation reported a data breach to the Montana Attorney General. The breach was reported on 2025-09-24. The breach occurred from 09/05/2025 to 09/07/2025. 40 Montana residents were affected.
- FEDERALSEC 8-Kas victim2025-09-23
Boyd Gaming Corporation filed an 8-K on September 23, 2025, disclosing a cybersecurity incident where an unauthorized third party accessed internal IT systems and exfiltrated employee and limited other individual data. The incident had no impact on business operations. The Company engaged external cybersecurity experts and federal law enforcement, and is notifying impacted individuals and regulators.