
Federal Judge Allows Class-Action Negligence Claims Against Rivers Casino Philadelphia to Advance
The US District Court for the Eastern District of Pennsylvania issued a ruling that permits a class-action negligence lawsuit against Rivers Casino Philadelphia, operated by Rush Street Gaming, to move forward while dismissing certain other claims. The decision centers on allegations that the casino failed to implement reasonable safeguards for employee personal information following a November 2024 cyberattack that exposed more than 2.56 terabytes of sensitive data on the dark web. According to court documents referenced in coverage from casino.org, the breach involved Social Security numbers, driver's licenses, passports, and banking details belonging to employees. The judge determined that the plaintiffs presented plausible claims under a negligence theory, allowing those portions of the case to proceed to the next stage of litigation.Details of the November 2024 Data Incident
The cyberattack took place in November 2024 and resulted in the unauthorized access and subsequent posting of extensive employee records on dark web forums. Investigators later confirmed that the compromised dataset exceeded 2.56 terabytes and contained highly sensitive identifiers that could facilitate identity theft or financial fraud. Casino management acknowledged the incident shortly after discovery, yet employees filed suit alleging inadequate protective measures had been in place prior to the event.
Those who filed the complaint asserted that the casino possessed an obligation to maintain industry-standard security protocols given the volume of personal information it collected and stored. Court records indicate the data appeared on illicit marketplaces within weeks of the intrusion, prompting immediate concerns among affected workers about long-term exposure risks.
Legal Claims Presented in the Class-Action Filing
The class-action complaint included multiple causes of action, among them negligence and breach of contract. Plaintiffs contended that Rivers Casino Philadelphia and its parent company, Rush Street Gaming, owed a duty of care to protect employee data and that this duty was breached when security protocols proved insufficient against the attack. Additional allegations referenced implied contractual promises arising from employment relationships and data-handling practices.
During preliminary motions, defense counsel sought dismissal of the entire suit, arguing that the claims lacked sufficient legal foundation. The court reviewed the pleadings and supporting materials before issuing its partial denial of the motion to dismiss.

Court's Analysis and Partial Dismissal
The federal judge examined whether the negligence allegations met the plausibility threshold required at this stage of litigation. After reviewing the facts alleged in the complaint, the court concluded that the plaintiffs had stated viable claims that the casino did not exercise reasonable care in safeguarding the data entrusted to it. This finding allows discovery and further proceedings on the negligence count to continue.
At the same time, the judge dismissed the breach-of-contract claims, determining that the complaint did not adequately establish the existence of an enforceable contractual obligation specific to data protection. Observers note that such selective outcomes are common in data-breach litigation where negligence theories often survive initial scrutiny while contract-based arguments require more explicit documentation of promises made.
The ruling does not address the ultimate merits of the case or determine liability; it simply permits the negligence portion to advance beyond the pleading stage. Legal teams for both sides are now positioned to exchange evidence and prepare for potential settlement discussions or trial.
Context Within Broader Data-Security Developments
Industry reports from gaming regulatory bodies indicate that casinos increasingly face scrutiny over cybersecurity practices because of the sensitive customer and employee information they maintain. In Pennsylvania, the Pennsylvania Gaming Control Board oversees licensing and operational standards, yet data-breach litigation typically proceeds through civil courts rather than regulatory channels alone.
Researchers studying similar incidents have documented patterns in which large-scale exposures of personally identifiable information lead to prolonged legal proceedings. The Rivers Casino Philadelphia matter follows this trajectory, with the class-action mechanism allowing numerous employees to pursue remedies collectively rather than through individual filings.
Conclusion
The decision from the US District Court for the Eastern District of Pennsylvania marks a significant procedural step in the litigation stemming from the November 2024 breach at Rivers Casino Philadelphia. With negligence claims cleared to proceed and contract claims dismissed, the case now moves into discovery where both parties will develop the factual record further. Affected employees retain the ability to seek redress through the class action, while the casino maintains its opportunity to contest the allegations on their merits as proceedings advance.