Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Boyd Gaming

Boyd Gaming Vendor Cyber Rating & Cyber Score

boydgaming.com

Boyd Gaming Corporation is one of the nation’s leading casino entertainment companies, but we’re so much more than that! We're a billion-dollar, publicly-traded company that retains the philosophy of a family-owned business, focused on creating long-term, sustainable growth for our shareholders. This philosophy defines and separates us from the competition, making us unique in our industry. From our beginnings in the 1970s, we made a commitment to our guests, employees, and communities to create a culture and an operating style built around that of a family-owned business. Even as a public company operating in a highly competitive industry, the Boyd Style of hospitality continues to define us. We currently own and operate 28 gaming


Boyd Gaming A.I CyberSecurity Scoring

Boyd Gaming
Company Information
Website:http://www.boydgaming.com
Employees number:6,934
Number of followers:70,839
NAICS:7132
Industry Type:Gambling Facilities and Casinos
Homepage:boydgaming.com
Boyd Gaming Risk Score (AI oriented)
Between 550 and 599
logo
Boyd GamingGambling Facilities and Casinos
Updated:
10/03/2026
562/1000
Very Poor
Ca
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Boyd Gaming Global Score (TPRM)
xxxx
logo
Boyd GamingGambling Facilities and Casinos
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Boyd Gaming
Boyd GamingVery Poor
Current Score
562Ca (VERY POOR)
01000
5 incidents
-54.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
583Before Incident
JULY 2026
582Before Incident
JUNE 2026
578Before Incident
MAY 2026
572Before Incident
APRIL 2026
572Before Incident
MARCH 2026
568Before Incident
FEBRUARY 2026
564Before Incident
JANUARY 2026
560Before Incident
DECEMBER 2025
553Before Incident
NOVEMBER 2025
551Before Incident
OCTOBER 2025
598Before Incident
Breach
02 Oct 2025Boyd Gaming
Boyd Gaming

Boyd Gaming Data Breach and Multiple Lawsuits

543After Incident
CRITICAL-55
BOY0532805100225
Boyd Gaming suffered a cyberattack where hackers infiltrated its IT systems, compromising sensitive data of current and former employees as well as a limited number of customers. The breach led to five class-action lawsuits, with plaintiffs alleging negligence in cybersecurity measures. Affected individuals reported increased spam calls and phishing attempts, while the company failed to notify some victims directly. Though casino operations remained unaffected, the breach exposed personal and employment-related data, triggering legal, financial, and reputational repercussions. The incident aligns with a broader trend of cyberattacks targeting Nevada’s gaming sector, including prior breaches at MGM Resorts and Caesars Entertainment. Boyd Gaming acknowledged the attack in a regulatory filing but did not disclose whether ransomware was involved or if a ransom was paid. The company is relying on cybersecurity insurance to cover costs, including investigations and potential penalties.
INCIDENT DETAILS -
TYPE
Data BreachCyberattack
IMPACT
IT infrastructureOperational Impact: None (casino operations remained unaffected)Multiple class-action lawsuits filed
DATA BREACH
Employee dataLimited third-party dataSensitivity Of Data: High (personal information)
SEPTEMBER 2025
649Before Incident
Breach
01 Sep 2025Boyd Gaming
Boyd Gaming Corporation

Boyd Gaming Corporation Data Breach (2025)

595After Incident
CRITICAL-54
BOY1692216092925
Boyd Gaming Corporation, a major casino and entertainment company, suffered a cyber breach in September 2025 where unauthorized actors infiltrated its internal systems and exfiltrated confidential data. The stolen information included employee records (such as Social Security numbers) and data from a limited number of other individuals. While casino and hotel operations remained unaffected, the breach triggered legal action from a former employee, Scott Levy, who filed a class-action lawsuit alleging negligence, breach of implied contract, and violations of Nevada’s Consumer Fraud Act. The lawsuit argues Boyd’s security measures were inadequate, as the company admitted personal data was stolen—not merely accessed. The incident follows a trend of escalating cyberattacks on the gaming sector, with prior high-profile cases like Caesars Entertainment (paid $15M ransom) and MGM Resorts (lost ~$100M in disruptions). Boyd is cooperating with cybersecurity experts and law enforcement, but the breach underscores growing legal, financial, and reputational risks tied to data exposure in the industry.
INCIDENT DETAILS -
TYPE
Data BreachUnauthorized Access
MOTIVATION
Data TheftPotential Financial GainFraud/Identity Theft
IMPACT
Employee RecordsCustomer RecordsSocial Security NumbersPersonally Identifiable Information (PII)Internal IT SystemsOperational Impact: None (casino and hotel operations remained unaffected)Brand Reputation Impact: Moderate (legal action and regulatory scrutiny)Lawsuit filed by former employee (Scott Levy)Potential class actionAllegations of negligence, breach of implied contract, unjust enrichment, and violations of the Nevada Consumer Fraud ActIdentity Theft Risk: High (Social Security numbers and sensitive data exposed)
DATA BREACH
Employee DataCustomer DataSocial Security NumbersPIISensitivity Of Data: High
MAY 2025
703Before Incident
Breach
01 May 2025Boyd Gaming
Boyd Gaming Corporation

Boyd Gaming Corporation Data Breach (2025)

639After Incident
CRITICAL-64
BOY1002810100425
Boyd Gaming Corporation, a major U.S. gambling and hospitality company operating 28 casinos and online gaming platforms, suffered a data breach in early September 2025. An unauthorized third party gained access to its internal IT systems between September 5–7, 2025, exfiltrating sensitive personally identifiable information (PII) of customers. The compromised data included names, addresses, Social Security numbers, driver’s license numbers, government-issued ID numbers (e.g., passports), and dates of birth. The breach impacted thousands of individuals across multiple states, with 4,300 affected in Texas alone. Boyd Gaming notified regulators, attorney general offices, and the U.S. Securities and Exchange Commission (SEC). While the company offered two years of free credit monitoring and identity protection services, the exposure of high-risk PII (e.g., SSNs, driver’s licenses) poses significant long-term risks, including identity theft, financial fraud, and unauthorized account access. Legal firms are investigating potential class-action lawsuits, as affected individuals may be entitled to compensation for the unauthorized exposure of their sensitive data, even if no immediate fraud has occurred. The breach underscores vulnerabilities in Boyd Gaming’s cybersecurity defenses, particularly given the targeted extraction of highly sensitive customer records by external threat actors.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Name of individualAddressSocial Security numberDriver’s license numberGovernment-issued ID number (e.g., passport, state ID card)Date of birthSystems Affected: Internal IT systemsBrand Reputation Impact: Potential reputational damage due to exposure of sensitive customer dataLegal Liabilities: Potential lawsuits and regulatory scrutiny (e.g., SEC, state attorneys general)Identity Theft Risk: High (due to exposure of SSNs, driver’s license numbers, and other PII)
DATA BREACH
Personally Identifiable Information (PII)Sensitive Identification DocumentsNumber Of Records Exposed: 4,325+ (exact total undisclosed)Sensitivity Of Data: High (includes SSNs, driver’s license numbers, and government-issued IDs)Data Exfiltration: YesPersonally Identifiable Information: Yes (names, addresses, SSNs, driver’s license numbers, government-issued IDs, dates of birth)
SEPTEMBER 2023
724Before Incident
Breach
01 Sep 2023Boyd Gaming
Boyd Gaming Corp.

Boyd Gaming Corp. Data Breach (September 2023)

669After Incident
CRITICAL-55
BOY5992559100125
Boyd Gaming Corp., a major Las Vegas-based casino operator with 11 properties in the Las Vegas Valley and additional locations across 10 U.S. states, suffered a cyberattack in early September 2023 (reportedly between September 5–7). The breach involved unauthorized access and exfiltration of employee data and records tied to a limited number of other individuals, including customers and former employees. The company delayed notifying victims, with lawsuits alleging negligence in safeguarding personal information and failing to disclose the breach promptly. Multiple class-action lawsuits—filed by employees, ex-employees, and customers from Nevada, Texas, Louisiana, and Ohio—accuse Boyd of breach of implied contract, negligence, invasion of privacy, and unjust enrichment. The SEC filing confirmed data theft, but Boyd has not clarified whether ransomware was involved or if a ransom was paid. The incident impacts thousands of individuals, raising concerns over financial fraud, identity theft, and reputational damage to the company. Plaintiffs claim Boyd intentionally obscured the breach’s scope, including how hackers accessed sensitive data and the duration of unauthorized access.
INCIDENT DETAILS -
TYPE
Data BreachCyberattack
MOTIVATION
Data TheftFinancial Gain
IMPACT
Personally Identifiable Information (PII)Employee RecordsMultiple Lawsuits FiledNegative PublicityLoss of TrustFour Class-Action Lawsuits (Nevada, Louisiana, Texas, Ohio)Allegations of NegligenceBreach of Implied ContractInvasion of PrivacyHigh (PII Exposed)
DATA BREACH
Personally Identifiable Information (PII)Employee RecordsNumber Of Records Exposed: Several ThousandSensitivity Of Data: High (PII)Data Exfiltration: YesNamesEmployee DataCustomer Data (potential)
JUNE 2023
787Before Incident
Breach
16 Jun 2023Boyd Gaming
Boyd Gaming

Boyd Gaming Data Breach and Class-Action Lawsuits

722After Incident
CRITICAL-65
BOY5993359100225
Boyd Gaming, a major casino entertainment company, suffered a cyber breach where an unauthorized third party infiltrated its IT systems and exfiltrated sensitive data belonging to current/former employees and a limited number of customers. The breach has triggered five class-action lawsuits, with plaintiffs—including employees and customers—alleging negligence in cybersecurity safeguards. The stolen data reportedly includes personal information, leading to increased spam calls and phishing attempts for affected individuals. While Boyd Gaming confirmed the incident in an SEC filing and claimed casino operations remained unaffected, it has not disclosed the exact timeline, scope of stolen data, or whether a ransom was paid. The company is relying on cybersecurity insurance to cover investigation costs, lawsuits, and potential regulatory fines. The breach aligns with a broader trend of cyberattacks targeting Nevada’s gaming industry, following similar incidents at MGM Resorts and Caesars Entertainment in 2023.
INCIDENT DETAILS -
TYPE
Data BreachUnauthorized Access
MOTIVATION
Financial GainData Theft
IMPACT
Employee DataCustomer DataInternal IT SystemsOperational Impact: None (casino operations unaffected)Customer Complaints: Increase in spam calls and phishing texts reported by at least one plaintiff (Scott Levy)Brand Reputation Impact: Negative (multiple class-action lawsuits filed, allegations of inadequate cybersecurity)Five class-action lawsuits filedPotential regulatory finesIdentity Theft Risk: High (plaintiffs report increased spam/phishing attempts)
DATA BREACH
Employee DataCustomer DataPersonally Identifiable Information (PII)Sensitivity Of Data: High (described as a 'treasure trove' of private information)Data Exfiltration: YesPersonally Identifiable Information: Yes

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Boyd Gaming ?
?
What was Boyd Gaming's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Boyd Gaming's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Boyd Gaming's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Boyd Gaming's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Boyd Gaming's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Boyd Gaming's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Boyd Gaming's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Boyd Gaming's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Boyd Gaming's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Boyd Gaming's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Boyd Gaming's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on Boyd Gaming's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Boyd Gaming ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Boyd Gaming's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Boyd Gaming Cyber Scoring History | Rankiteo