Federal Judge Clears Path for Negligence Claim in Rivers Casino Philadelphia Data Breach Case

Drew Lorenz · Aug 11, 2026

Federal Judge Clears Path for Negligence Claim in Rivers Casino Philadelphia Data Breach Case

Exterior view of Rivers Casino Philadelphia building with signage and surrounding area

A federal judge in the US District Court for the Eastern District of Pennsylvania has allowed a class-action negligence lawsuit against Rivers Casino Philadelphia to move forward after a November 2024 cyberattack exposed more than 2.56 terabytes of employee data on the dark web, and the decision centers on claims that the casino failed to adequately protect sensitive personal information including Social Security numbers, driver’s licenses, and banking details.

The ruling comes after plaintiffs filed suit alleging that the breach led to identity theft and increased spam for affected workers, while the casino owned by Rush Street Gaming maintained that such incidents occur frequently across industries and bear no direct connection to its security practices, yet the court identified enough basis to let the negligence portion advance even as it dismissed breach of contract and invasion of privacy counts.

Details of the Cyberattack and Data Exposure

The November 2024 incident resulted in a massive dump of employee records appearing on dark web forums, and investigators traced the material to a breach at the Philadelphia casino where threat actors gained access to systems holding extensive personal identifiers, which quickly surfaced in illicit marketplaces and prompted immediate legal action from current and former staff members who claimed resulting harm.

Those who studied the leaked files noted that the volume exceeded 2.56 terabytes, encompassing not only basic contact information but also highly sensitive elements such as full Social Security numbers alongside scanned driver’s licenses and direct banking records, and this scale distinguished the event from smaller incidents reported elsewhere in the gaming sector during the same period.

Court’s Analysis of Claims

Judge rulings emphasized that plaintiffs presented sufficient allegations to support a negligence theory, particularly around whether the casino implemented reasonable safeguards against foreseeable cyber threats, while the dismissal of breach of contract arguments stemmed from the absence of an explicit contractual duty tied to data protection in employment agreements, and invasion of privacy claims fell short because the court found no evidence of intentional disclosure by the operator itself.

Plaintiffs’ filings described concrete instances of identity theft and a surge in unsolicited communications following the breach, and they argued these outcomes directly flowed from the casino’s handling of their information, yet the defense countered that similar problems arise independently in the broader digital environment and cannot be causally linked without additional proof.

Interior of a casino floor showing slot machines and gaming tables with patrons

Arguments Presented by Both Sides

Rush Street Gaming representatives asserted that cyber incidents of this type reflect industry-wide challenges rather than unique lapses at Rivers Casino Philadelphia, and they pointed to the common occurrence of data appearing on dark web platforms after various corporate breaches, whereas plaintiffs highlighted specific security shortcomings they believe left employee records vulnerable during the attack window.

Legal observers note that the court’s decision to sustain the negligence claim allows discovery to proceed on issues such as the casino’s prior cybersecurity measures, employee training protocols, and response timelines, and this phase will determine whether the evidence supports findings of unreasonable conduct under Pennsylvania law.

Implications for Data Security Practices

Similar cases in other jurisdictions have turned on comparable questions of reasonable care in protecting personal data, and the Eastern District of Pennsylvania ruling aligns with a growing body of decisions that permit negligence theories to advance when plaintiffs demonstrate plausible links between a breach and subsequent harms, while contract and privacy claims often require stricter showings of duty or intent.

According to reporting from casino.org, the exposed records included banking information that could facilitate direct financial fraud, and plaintiffs have cited examples where affected individuals encountered unauthorized account activity shortly after the dark web posting.

Next Steps in the Litigation

With the negligence claim cleared for further proceedings, the case enters a discovery stage where both parties will exchange evidence on security practices and causation, and the court has signaled that additional motions may address class certification once more facts emerge about the scope of affected employees.

Defense attorneys have indicated plans to challenge causation at later stages by showing that identity theft and spam patterns predate the breach or stem from unrelated sources, whereas plaintiffs intend to present expert analysis linking the specific data types released to documented instances of misuse.

Conclusion

The decision keeps the core negligence allegations alive while narrowing the lawsuit to that single viable theory, and it underscores how courts continue to scrutinize data-handling responsibilities in the gaming industry without automatically extending liability across every asserted claim, with proceedings now focused on building the factual record around the November 2024 events at Rivers Casino Philadelphia.