Skip to content

Nevada’s Eureka Casino settles $1 million data breach case

Jefferson Mendoza
Written by Jefferson Mendoza

Eureka Casino has agreed to a $1 million class action settlement following claims that it failed to prevent a November 2022 data breach that exposed sensitive customer information.​

Between 9 November and 13 November 2022, hackers accessed personal data, including names, Social Security numbers, financial account details, passport numbers, and driver’s licence information.​

Allegations against Eureka Casino

Nevada enforces some of the nation’s strictest data breach laws, designed to protect residents’ personal information and hold businesses accountable. The Nevada Revised Statutes (NRS) Chapter 603A stipulates that companies must implement reasonable security measures.

Plaintiffs alleged that Eureka Casino failed to meet these standards, violating both contractual obligations and state notification laws, as reported by several media outlets.​

Businesses are required to notify affected individuals—and in certain cases, the Nevada Attorney General’s Office and credit reporting agencies—when data is compromised. The Attorney General has authority under NRS 603A.290 to act against non-compliant businesses.​

Additionally, the Nevada Privacy of Information Collected on the Internet from Consumers Act (NRS 603A.300–603A.360) requires online services to provide clear notices when collecting personal data. While Eureka Casino did not admit wrongdoing, it agreed to settle the case.

Other states like California go further by granting consumers a private right of action and statutory damages.

​Settlement terms

According to the lawsuit, class members may claim up to $5,000 for documented monetary losses linked to the breach, provided the losses occurred between 9 November 9 and 11 May  2026, and reasonable efforts were made to mitigate them.​

Eureka Casino must also compensate residents in California. Eligible class members during the breach period may receive an additional $100 cash payment, but it is subject to pro rata adjustment if claims exceed the settlement fund. Additionally, remaining funds will be distributed among valid claims after reimbursement and statutory payments.​ Key deadlines for exclusion and objections are 9 April 2026, while the final approval hearing is set on 10 June 2026.​

(Source: Grand View Research)

Data breaches: A recurring issue

Eureka Casino is not alone. Data breaches have become increasingly common in the casino and hospitality industry due to the nature of having to handle vast amounts of personal information.

According to several media outlets, Wynn Resorts confirmed a breach last month after hackers removed data from a leak site. The incident raised concerns about customer notification and whether ransom payments were made.​

Boyd Gaming also fell victim to a cyberattack in 2025, with employees’ and customers’ data having been compromised. While operations did continue, the company faced investigation, legal, and regulatory costs, with its insurance expected to compensate.​

Between 2018 and 2020, the Marriott and Starwood incident was considered to be one of the largest hospitality breaches, affecting hundreds of millions of guests. It underscored the risks of a poor supply chain, critically examining the weak infrastructure security.

Stockton University revealed in its studies that casinos and hotels remain prime targets due to complex IT systems that integrate gaming, hospitality, and online booking platforms. These multiple entry points, combined with gaps in employee training, leave businesses vulnerable to phishing and social engineering attacks.

Stay in the loop and join the biggest iGaming Community in the world with SiGMA’s Top 10 news countdown. Subscribe HERE for weekly updates from the world’s iGaming authority and exclusive subscriber-only offers.