Crystal Bay Casino
ent_25e6bc0ba645ca68d044cec9
Disclosures
9
State AG · 7 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
93,950
as filed · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Crystal Bay Casino
- Normalized
- crystal bay casino— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (9)newest first
- ⛰️New Hampshire State AGas victim2023-04-03
Crystal Bay Casino filed a supplemental notice with the New Hampshire Attorney General regarding a data event in November 2022. Unauthorized copying of files and database information occurred around November 27, 2022. The incident affected 128 New Hampshire residents, involving names and dates of birth. The casino reported the incident to the FBI, engaged in forensic investigation, and provided credit monitoring services to affected individuals.
- 🐻California State AGas victim2023-03-29
Crystal Bay Casino (Crystal Bay, NV) notified affected individuals in February 2023 of a data security incident in which certain files and database records may have been copied from their systems on or around November 27, 2022, with additional database exfiltration identified as of January 25, 2023. The incident involved unauthorized copying of personal information including names. The FBI was notified. Approximately 40 Rhode Island residents were among those potentially impacted.
- 🦞Maine State AGas victim2023-03-29
Crystal Bay Casino reported an external system breach that occurred on November 27, 2022, and was discovered on January 25, 2023. The breach affected 93,950 individuals, compromising names and driver's license or non-driver ID card numbers. The casino offered affected individuals 12 months of credit monitoring and identity restoration services through IDX.
- 🍁Vermont State AGas victim2023-02-24
Crystal Bay Casino notified consumers of a November 2022 incident where files were copied from its systems. The breach potentially exposed names and other personal information. The casino reported the incident to the FBI and is offering complimentary credit monitoring services to affected individuals.
- 🦫Oregon State AGas victim2023-02-24
Crystal Bay Casino reported a data breach to the Oregon Attorney General. The breach was reported on 2023-02-24. The breach occurred during 11/27/2022 - 11/27/2022. The breach was discovered on 1/25/2023. 86,291 individuals were affected. Notice was sent on 2/24/2023.
- 🦬Montana State AGas victim2023-02-24
Crystal Bay Casino reported a data breach to the Montana Attorney General. The breach was reported on 2023-02-24. The breach occurred from 11/27/2022 to 2/7/2023. 143 Montana residents were affected.
- 🦞Maine State AGas victim2023-02-24
Crystal Bay Casino reported a data breach that occurred on November 27, 2022, and was discovered on January 25, 2023. The breach was an external system breach (hacking) that affected 86,291 individuals, including 54 Maine residents. The compromised information includes names and driver's license or non-driver identification card numbers. Crystal Bay Casino offered 12 months of credit monitoring and identity restoration services through IDX to the affected individuals.
- 🐻California State AGas victim2023-02-24
Crystal Bay Casino notified individuals that their information may have been copied from its systems on or around November 27, 2022. The casino identified unusual activity in November 2022 and initiated an investigation. Affected data includes names and potentially other personal information. The company reported the incident to the FBI and is offering complimentary credit monitoring.
- 🌲Washington State AGas victim2023-02-24
Crystal Bay Casino, a business sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2023-01-25 and filed notice on 2023-02-24. 1,480 Washington residents were affected. 30 days elapsed between awareness and notification. 59 days to identify the breach. 0 days to contain the breach.