Rivers Casino Philadelphia Data Breach Notice (Oregon Attorney General)
If you received a notice from Rivers Casino Philadelphia, here’s what the filing says was exposed, and what to do about it.
Rivers Casino Philadelphia notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on February 28, 2025. The filing puts the incident itself on October 14, 2024.
The personal information of 1,942,182 people was exposed in a breach at Rivers Casino Philadelphia. The incident occurred on October 14, 2024. The organisation filed its notification with the Oregon Department of Justice on February 28, 2025 — 137 days later.
What the 137-day gap means for you
That interval between the breach date and the official filing is the single most striking fact in the record. While notification deadlines vary by state and depend on when an investigation concludes, nearly four and a half months is long enough that many people will want to treat the exposure as having happened months ago. The filing does not state when Rivers Casino Philadelphia first discovered the incident, so the only reliable way to know whether your information was involved is the letter the organisation is required to send directly to affected individuals, usually by post.
If you have not received such a letter at your address as it existed on October 14, 2024, it is likely your records were not included. However, anyone who has moved since the incident should contact Rivers Casino Philadelphia directly to confirm their status.
The only category the filing names
The record lists one broad category: personal information. No passwords, no financial account numbers, no Social Security numbers, no driver’s license numbers, and no medical details appear in the filing. This is genuinely good news. Because no credentials were exposed, there is no need to change any password connected to Rivers Casino Philadelphia as a result of this incident.
Personal information in this context typically means name combined with contact details and other identifying data that cannot be reissued like a credit card. Once it has left the organisation’s control, it remains available for identity thieves and fraudsters to use for years. That permanence is what matters most now.
How exposed personal information is used against you
Names and addresses alone are valuable to criminals building synthetic identities or impersonating you in low-level fraud. They can be paired with information obtained elsewhere to file fraudulent tax returns, open utility accounts, or apply for government benefits in your name. Because the filing does not list government identifiers such as Social Security numbers, the most severe forms of identity theft are less likely — but not impossible if the attackers already hold other pieces of your data from previous breaches.
The absence of passwords and financial account numbers in the disclosed categories means this breach does not put your existing accounts at direct risk of takeover. The threat is longer-term and quieter: your name and contact details can be added to databases that criminals sell and resell for years.
What you can still control
You cannot make the exposed personal information disappear, but you can limit what criminals can do with it. Start by placing a freeze on your credit reports at the three major bureaus. This prevents new accounts from being opened in your name without your explicit permission. The freeze is free, reversible, and the single most effective step available when personal information has been exposed.
Next, enable two-factor authentication everywhere it is offered, especially on financial, tax, and government accounts. While this breach did not expose credentials, strong authentication remains the best defense against future attempts that may use your personal details.
Review your Explanation of Benefits statements from health insurers even though medical information is not listed in the filing. Criminals sometimes test stolen personal data by attempting to file false medical claims. Catching unusual activity early limits damage.
Set up alerts with the major credit bureaus and your banks so you are notified of any new inquiries or account openings. Early warning gives you time to respond before fraudulent activity escalates.
Finally, be wary of unexpected calls, texts, or emails that reference Rivers Casino Philadelphia or appear to come from Oregon government agencies. Criminals often use breached personal information to make phishing attempts more convincing. When in doubt, contact the organisation or agency directly using a known good number rather than replying to the message.
The letter from Rivers Casino Philadelphia remains the definitive answer for whether you were among the 1,942,182 people whose personal information was exposed. Treat its absence as meaningful, but verify directly if you have changed addresses since October 14, 2024. The exposure cannot be undone, yet the absence of credentials and permanent identifiers in the record leaves you with more protection than many breach victims receive.
Report details & sourcing
Related breaches
Livara Health Medical Group Data Breach Notice (California Attorney General)
Livara Health Medical Group notified California residents of a data breach in a filing reported to t…
Pan American Group LLC Data Breach Notice (California Attorney General)
Pan American Group LLC notified California residents of a data breach in a filing reported to the Ca…
Punch & Associates Investment Management, Inc. Data Breach Notice (Vermont Attorney General)
Punch & Associates Investment Management, Inc. notified Vermont residents of a data breach in a fili…