Rivers Casino Philadelphia Faces Class Action Lawsuit Over Data Breach
AI-GENERATEDA federal judge has cleared the way for a negligence lawsuit against Rivers Casino Philadelphia after a January cyberattack exposed customer social security numbers and bank details.
Cybersecurity in the gambling industry has once again become a focal point for the judiciary. Following a serious incident in January of this year, Rivers Casino Philadelphia must now face a class action lawsuit. US District Judge Joshua D. Wolson of the US District Court for the Eastern District of Pennsylvania ruled that the negligence claims against the casino operator are sufficiently grounded to warrant a trial. Customers of the establishment sued after unauthorized parties gained access to servers and potentially copied highly sensitive files.
The scope of the data leak is significant, as the affected files contained names, bank details, and even social security numbers. Such records are highly sought after on the black market as they form the basis for identity fraud. Although the casino notified affected individuals after the incident, the plaintiffs accuse the company of concealing the true extent of the attack. Judge Wolson emphasized in his decision that operators have a clear duty of care in protecting customer data and that the plaintiffs plausibly alleged that this duty was breached.
Numbers and facts
The current case joins a series of cyberattacks on the US gambling industry. While the exact number of affected customers in the Rivers Casino Philadelphia case was not finalized in the current court ruling, a look at similar incidents shows the dimensions. The law firm Levi & Korsinsky LLP, which is handling the class action, called on affected parties to join the lawsuit. A comparison with the Wynn Resorts case illustrates the danger: there, the group ShinyHunters gained access to approximately 800,000 records and demanded a ransom of 1.5 million US dollars by a deadline in February. In the Rivers Casino case, the judge dismissed claims for unjust enrichment or invasion of privacy but upheld the negligence charge, as plaintiffs already reported increased fraudulent attempts following the leak.
"The plaintiffs had plausibly alleged that it failed to meet that obligation to exercise reasonable care when protecting customers' personal information." - Joshua D. Wolson, US District Judge
Background
Casinos are extremely attractive targets for cybercriminals. A study by UNLV (University of Nevada, Las Vegas) proves that there were more than 50 confirmed cyber incidents involving gambling companies in Nevada between 2007 and 2023. Most of these occurred in the last decade. Often, the IT infrastructure is based on antiquated technology, making it easier for attackers to gain access. The core of the current proceedings against Rivers Philadelphia is whether the company had implemented state-of-the-art protective measures. Judge Wolson saw the reports of attempted fraudulent activities following the incident as sufficient evidence to continue the trial. Other legal claims, such as breach of confidence, were dismissed due to insufficient grounds.
Why it matters for German players
For German players active in online casinos with a license from the Gemeinsame Glücksspielbehörde der Länder (GGL), data security is an even higher priority. The State Treaty on Gambling 2021 (GlüStV 2021) prescribes extremely strict technical requirements. Every player must be registered via the central LUGAS system to monitor deposit limits of a maximum of 1,000 euros per month and the stake limit of 1 euro per spin on virtual slots. This linking of personal data with state monitoring systems means that German licensees carry immense responsibility. A data leak like the one in Philadelphia would be a regulatory nightmare in this country, potentially leading to the immediate withdrawal of the GGL license. Players in Germany enjoy one of the highest protection standards worldwide due to GDPR and GGL supervision, which marks the difference from less regulated MGA or Curacao providers.
What it means for GGL-licensed casinos
German providers on the official whitelist must ensure that their interfaces to LUGAS and the OASIS blocking file are not only functional but also encrypted according to the latest standards. The incident at Rivers Casino shows that courts are increasingly willing to hold operators directly liable for IT deficiencies. For GGL casinos, this means a constant obligation to invest in cybersecurity to avoid damage claims modeled after US class actions. IT systems must be regularly audited, as the GGL can impose sensitive fines for security defects. In Germany, transparency towards authorities in the event of an attack is also strictly regulated by legal reporting requirements compared to many US states.
Frequently asked questions
Why is Rivers Casino Philadelphia being sued?
Customers accuse the casino of failing to adequately protect their personal data, such as names and social security numbers, during a cyberattack in January. A federal judge has now ruled that the allegation of negligence must be heard in court.
What data was stolen in the hacker attack?
According to the lawsuit, unauthorized persons had access to files containing the names, bank details, and social security numbers of casino visitors. The plaintiffs are already reporting an increase in attempted fraudulent activity following the incident.
What do the courts say about casino liability for data leaks?
Judge Joshua D. Wolson stated that operators have a duty of care toward their customers. If security measures are inadequate and damages from identity theft are threatened as a result, class action lawsuits based on negligence can be admitted.
Are German online casinos safe from such attacks?
No system is 100 percent secure, but providers with a GGL license must meet extremely high IT security standards in Germany. Regulation by the GlüStV 2021 and the connection to LUGAS require the strictest encryption and regular audits to protect German players as best as possible.
Share
About the author

Lisa Lustich
Editor-in-chief & casino tester
Lisa Lustich has been testing German-language online casinos since 1997 and runs the Lustich.de newsroom. More than 400 published reviews, certified player-protection advisor (BZgA training, 2019).
All articles by Lisa Lustich →Sources & further reading
- Joint Gambling Authority of the German Federal States (GGL): gluecksspiel-behoerde.de
- Whitelist of permitted online operators: GGL-Whitelist
- BZgA problem-gambling helpline: 0800 1 372 700 (free, anonymous, 24/7)
- Editorial methodology: Editorial guidelines Lustich.de
Gambling can be addictive. Please play responsibly. Help and counselling at 0800 1 372 700 (BZgA, free & anonymous).
Read this article in 25 languages
Related topics
Further Reading
AI-GENERATEDKonami Gaming achieves ISO 27001 certification for SYNKROS and iGaming
Konami Gaming has secured the globally recognized ISO 27001 certification for information security, setting new standards for casino management and online gaming.
AI-GENERATEDHyper-Localization: Slotegrator Launches New Frontend Tools for LatAm
Slotegrator's Casino Builder module now allows operators to instantly adapt platforms for the Latin American market, featuring over 20,000 games.
AI-GENERATEDRollcard for High Rollers: Grandstand Launches Visa Debit Card with Million-Dollar Limit
Fintech firm Grandstand Limited (Nasdaq: GRSD) has launched Rollcard, a Visa debit card designed for high rollers with daily spend limits of up to $1,000,000.










