DataBreachCaseFile.com
MonitoringVermont AG filing · September 24, 2026

Boyd Gaming Reports Data Security Incident to Vermont Regulators 2026

Boyd Gaming Corporation recently informed Vermont authorities of a data security incident. This compromise potentially exposed sensitive personal information, including Full Name, Social Security Number, and Financial Account details. Individuals impacted by this breach face heightened risks of identity theft and financial fraud.

State
Vermont
Reported
September 24, 2026

What may have been exposed

  • Full Name
  • Social Security Number
  • Date of Birth
  • Driver's License or Government ID Number
  • Financial Account and Banking Details
  • Payment Card Information
  • Loyalty Program and Account Credentials
  • Home Address and Contact Information

Boyd Gaming Corporation, a prominent gaming and hospitality operator, filed a data security incident report with the Vermont Attorney General on September 24, 2026. The company stated an unspecified breach type led to the compromise of its digital network infrastructure. This report serves to notify consumers and regulatory bodies about the unauthorized access.

The data reported as potentially exposed in this incident includes Full Name, Social Security Number, Date of Birth, Driver's License or Government ID Number, Financial Account and Banking Details, Payment Card Information, Loyalty Program and Account Credentials, and Home Address and Contact Information. These categories represent a wide range of sensitive personal and financial identifiers.

The exposure of such comprehensive personal data creates immediate and long-term risks for affected individuals. Compromised Social Security Numbers and Driver's License or Government ID Numbers significantly increase the risk of identity theft, which can lead to fraudulent credit applications, unauthorized loans, and tax fraud. Financial Account and Banking Details, along with Payment Card Information, may be used for direct financial theft.

Furthermore, the theft of Loyalty Program and Account Credentials, combined with Home Address and Contact Information, can facilitate sophisticated phishing attempts and social engineering schemes. These could be designed to gain access to additional accounts or trick individuals into revealing more sensitive data.

Individuals who receive notification about this breach should take proactive steps to protect themselves. It is advisable to review financial account statements and credit reports regularly for any unauthorized activity. Consider placing a fraud alert or credit freeze with the major credit bureaus. Be cautious of unsolicited emails, calls, or messages requesting personal information, as these could be phishing attempts.

What to do if you were affected

Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.

  • Freeze your credit

    Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.

  • Watch your financial accounts

    Review bank and card statements for unfamiliar activity and turn on transaction alerts. Report anything you don't recognize to your bank right away.

  • Replace exposed ID documents

    Contact your state DMV or the issuing agency about replacing an exposed driver's license, passport, or government ID number.

  • Secure your online accounts

    Change the password on any account that reused an exposed password and turn on two-factor authentication wherever it's offered.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Source: Vermont Attorney General filing

Related data breach cases