Federal Judge Clears Path for Negligence Claims in Rivers Casino Philadelphia Data Breach Lawsuit
Rosa Klein · Aug 11, 2026

Federal Judge Clears Path for Negligence Claims in Rivers Casino Philadelphia Data Breach Lawsuit

A federal judge in the US District Court for the Eastern District of Pennsylvania has allowed a class-action negligence lawsuit to move forward against Rivers Casino Philadelphia after a November 2024 cyberattack exposed more than 2.56 terabytes of employee data on the dark web, and the decision came after the court reviewed evidence showing that Social Security numbers, driver’s licenses, and banking information had been compromised during the incident while the casino argued that resulting identity theft and spam complaints stemmed from unrelated common issues.
Background on the November 2024 Incident
The breach occurred in November 2024 when unauthorized actors accessed and posted a substantial volume of sensitive employee records belonging to the casino, which operates under ownership by Rush Street Gaming, and court documents indicate that the exposed materials included personal identifiers that plaintiffs later connected to instances of identity theft along with increased spam activity following the event.
Legal Claims and Court Analysis
Plaintiffs filed the class-action suit alleging negligence among other causes of action, yet the court determined that only the negligence portion presented sufficient grounds to proceed while it dismissed breach of contract and invasion of privacy claims because those lacked the required legal foundation under the judge’s evaluation of the facts presented during preliminary motions, and this ruling establishes that the case can advance on the negligence theory alone as the litigation enters its next phase.
The casino countered in its filings that problems such as identity theft and spam occur frequently in the broader digital environment and bear no direct connection to the November 2024 event, but the court found that these arguments did not eliminate the possibility of a viable negligence claim at this stage of the proceedings.

Plaintiff Allegations and Casino Response
Those bringing the suit described specific harms including instances of identity theft and surges in unsolicited communications that they attribute to the data exposure, and they contend that the casino failed to implement adequate protective measures prior to the attack, whereas Rush Street Gaming maintained that such outcomes reflect widespread challenges rather than failures unique to its operations at the Philadelphia location.
Evidence submitted to the court included details about the volume and nature of the compromised files, which amounted to over 2.56 terabytes posted publicly on dark web platforms, and this documentation helped establish the scope that supported continuation of the negligence portion of the complaint while other elements were set aside.
Next Steps in the Litigation
With the negligence claim cleared to proceed, the parties now move toward discovery and potential settlement discussions or trial preparation, and observers note that the Eastern District of Pennsylvania has handled similar data-related matters in the past which provides a framework for how this case may unfold over the coming months as of August 2026 when updates on scheduling orders are anticipated.
According to reports covering the filing, the ruling reflects standard judicial scrutiny applied to class-action complaints involving cybersecurity incidents, and it leaves open the possibility for plaintiffs to seek damages tied specifically to the alleged negligence without the additional claims that were removed from consideration.
Conclusion
The decision by the federal judge marks a defined boundary for the scope of the lawsuit, allowing the negligence allegations to advance while closing off the other asserted causes of action, and this outcome sets the stage for further legal examination of the casino’s data protection practices in relation to the November 2024 breach that placed employee information into public view on the dark web.