getpaycasino.com

The authoritative voice in premium online gaming, slots analysis, and responsible play strategies.

Federal Court Allows Negligence Claims in Rivers Casino Philadelphia Data Breach Lawsuit to Advance

Katja Koch · Aug 11, 2026

Federal Court Allows Negligence Claims in Rivers Casino Philadelphia Data Breach Lawsuit to Advance

Exterior view of Rivers Casino Philadelphia with signage and surrounding area

A federal judge in the US District Court for the Eastern District of Pennsylvania has ruled that a class-action negligence lawsuit against Rivers Casino Philadelphia, owned by Rush Street Gaming, can proceed following a major cyberattack in November 2024 that exposed over 2.56 terabytes of employee personal data and later appeared on the dark web, while other claims including breach of contract were dismissed by the court.

The decision centers on allegations that the casino failed to protect sensitive information belonging to employees, which included Social Security numbers, driver’s licenses, passports, and banking details, and the ruling permits plaintiffs to pursue negligence claims based on those asserted failures in data security practices.

Background of the November 2024 Cyberattack

The incident occurred in November 2024 when unauthorized access led to the theft of extensive employee records at Rivers Casino Philadelphia, and those records totaling more than 2.56 terabytes eventually surfaced on dark web forums where such data often circulates among malicious actors, according to court filings and notifications issued later.

Casino management responded by notifying affected employees in January 2025 about the breach, at which point the company offered credit monitoring services to those impacted, yet plaintiffs in the class action maintain that the exposure has already led to instances of fraud and increased spam targeting the individuals whose information was compromised during the attack.

Details of the Class-Action Lawsuit

Employees filed the class-action complaint alleging negligence in the casino’s handling of personal data, and they pointed to resulting harms such as fraudulent activity and unwanted solicitations that they attribute directly to the breach, while the court separately dismissed breach of contract claims along with certain other counts that did not meet the required legal thresholds for continuation.

Observers note that the remaining negligence portion of the suit focuses on whether the casino implemented reasonable safeguards prior to the attack, and the judge determined that the plaintiffs had presented enough factual assertions to allow that specific claim to move forward into discovery and potential trial phases.

Courtroom interior with judge's bench and legal documents on desk

The Court’s Ruling and Its Implications

In the Eastern District of Pennsylvania, the federal judge evaluated the motion to dismiss and concluded that the negligence allegations could advance because they adequately described a duty of care, a breach of that duty through insufficient cybersecurity measures, and resulting damages tied to the exposed data, whereas the contract-based claims lacked the necessary elements to survive the same review.

Those involved in the case have seen the ruling keep the core dispute alive at a time when data protection standards in the gaming sector continue to draw scrutiny from regulators and litigants alike, and the proceeding now enters the next stage where evidence gathering will examine the casino’s security protocols in place during the period leading up to November 2024.

Additional context from the filings shows that the dark web posting of the stolen information occurred after the initial intrusion, which prompted the January 2025 notifications, and plaintiffs argue that the offered credit monitoring has not fully mitigated ongoing risks associated with the compromised records that include highly sensitive identifiers.

Next Steps in the Legal Process

With the negligence claim cleared to proceed, both sides will engage in discovery processes that include document exchanges and depositions focused on the casino’s data handling practices, and the court has set the stage for further motions or settlement discussions that could shape the outcome before any trial date is established.

Legal analysts tracking similar cases note that rulings of this nature often hinge on the specificity of allegations regarding security shortcomings, and here the judge found sufficient detail in the negligence portion to deny dismissal on those grounds alone while trimming other elements of the complaint.

Conclusion

The federal court decision keeps the class-action negligence suit against Rivers Casino Philadelphia active and allows plaintiffs to seek further accountability over the November 2024 breach that exposed extensive employee data, while the dismissal of breach of contract and related claims narrows the issues that will be litigated going forward in the Eastern District of Pennsylvania.