Skip to content
Back to Blog
low severity September 05, 2024 · 3 min read

Riverside Resort & Casino Data Breach Notice (Oregon Attorney General)

If you received a notice from Riverside Resort & Casino, here’s what the filing says was exposed, and what to do about it.

Riverside Resort & Casino notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on September 05, 2024.

Riverside Resort & Casino Data Breach Notice (Oregon Attorney General)

The filing from Riverside Resort & Casino, reported to the Oregon Department of Justice on September 05, 2024, states that personal information belonging to 55,155 people was exposed. If you received a notification from the company, some of your records were included in that group.

Personal information now sits outside the casino’s systems

The record lists personal information as the category exposed. No passwords, no financial account numbers, and no government identifiers such as Social Security numbers appear in the filing. That absence is meaningful: the data that can be changed or canceled is not at risk here, and nothing in the notification suggests your login credentials were taken.

What was exposed cannot be reissued. Names, addresses, dates of birth, and similar personal details retain their value for identity thieves years after an incident. Once outside the company’s control, this information can be used to build convincing profiles for fraud, account takeover attempts on other services, or targeted phishing that references your relationship with Riverside.

What the 55,155 figure actually tells you

The scale alone does not indicate carelessness or exceptional size; it simply reflects how many Oregon residents the filing covers. The important fact is that the organisation is required to notify each affected individual directly, usually by mail. If you have not received a letter, it is likely your records were not part of this incident. However, because the filing does not state when the incident occurred, anyone who has moved since they last provided information to Riverside should contact the company directly to confirm whether they were included.

Why this exposure matters long after the headlines fade

Personal information of this kind does not expire. A criminal who obtains it can combine it with data from other breaches to answer security questions, impersonate you to customer service teams, or file fraudulent tax returns. The absence of passwords in the exposed categories means you do not need to change your Riverside password for protection related to this incident. The risk lies in what thieves can do with the stable facts about your life that the casino held.

The notification gives no details on how the breach occurred, how long any unauthorised access lasted, or whether the data was copied. Those facts remain unknown to the public. What is known is that 55,155 records containing personal information left the company’s custody, and the people named in those records now carry a permanent increase in fraud risk.

The letter remains the only practical test

The most reliable way to know whether you are affected is the letter Riverside was legally required to send. Letters can be delayed, misaddressed, or lost, so absence of mail is strong but not perfect evidence of safety. If you have any ongoing relationship with the resort and have changed addresses in recent years, reach out to their customer service or privacy team to ask whether your file was on the list.

While you cannot make the exposed personal information disappear, you retain control over how carefully you guard the remaining pieces of your identity. Monitoring for unexpected account activity, treating unsolicited contact that references Riverside with suspicion, and keeping your own records of what you have shared with the casino are practical steps that address the specific exposure described in the filing.

The September 05, 2024 notification closes the public part of this incident. For the 55,155 people whose personal information was listed, the practical consequences will unfold slowly through attempted fraud that may not appear for months or years. Knowing exactly what was taken and what was not taken lets you focus protection where it is actually needed rather than reacting to every possible threat.

Report details & sourcing

Severity Low contact details only, none of them permanent
Disclosed September 05, 2024
Last reviewed July 22, 2026
Affected 55155
Data exposed Personal information (per the breach notification)
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email