Global hospitality and entertainment company Delaware North has disclosed a data breach that exposed the personal information of individuals after an unauthorized actor compromised an employee's Microsoft account and stole copies of certain files. The company confirmed the incident in notification letters filed with the New Hampshire and Texas Attorneys General, and began mailing notices to affected individuals on June 5, 2026. The breach is now the subject of a class-action investigation by attorneys working with ClassAction.org.
What Happened
Delaware North identified suspicious activity in an employee's Microsoft account on January 28, 2026. The subsequent investigation determined that an unauthorized actor had accessed the account and stolen copies of certain files the day prior, on January 27. The intrusion window was short, but it was enough time for the attacker to exfiltrate data before the activity was detected.
It took the company roughly four months to complete its review of the affected files. On May 28, 2026, Delaware North determined that the exfiltrated files contained personal information belonging to individuals, and notification letters began going out on June 5. Delaware North operates over 200 hotels, casinos, restaurants, sports venues, and other locations worldwide, giving the company a large pool of employees, guests, and partners whose data it holds.
What Was Taken
Based on regulatory filings, the stolen files may have contained the following categories of personal information:
- Full names
- Driver's license numbers
- State-issued identification numbers
- Social Security numbers (per the filing submitted to the Texas Attorney General's Office)
This combination is highly sensitive. Names paired with Social Security numbers and government-issued ID numbers form a near-complete identity kit, the exact data set that enables synthetic identity fraud, fraudulent credit applications, and tax fraud. Unlike a password, these identifiers cannot simply be reset, which extends the risk window for affected individuals for years.
Why It Matters
The Delaware North incident is a textbook example of how a single compromised cloud identity can lead to a wide-reaching data exposure. The attacker did not need to breach a network perimeter or deploy ransomware; they only needed valid access to one employee's Microsoft account to reach and exfiltrate files containing regulated personal data.
The timeline is also instructive for defenders. The actual theft occurred on January 27, detection followed within a day, but full scoping of the exposed data took until late May. That four-month lag between detection and notification is common in cloud data-theft cases, where reconstructing exactly what an attacker touched is slow and labor intensive. For affected individuals, it means their data was in criminal hands long before they were warned.
The Attack Technique
The breach centered on a compromised Microsoft account belonging to an employee. While Delaware North has not publicly detailed how the credentials were obtained, account compromises of this type are most commonly the result of phishing, credential stuffing using passwords leaked in prior breaches, session-token theft, or social engineering of help-desk staff to bypass multi-factor authentication.
Once inside a Microsoft 365 environment, an attacker with a single set of valid credentials can often reach files stored in OneDrive, SharePoint, and email attachments, then quietly download copies. The fact that the actor stole files rather than deploying disruptive malware suggests a financially motivated data-theft operation focused on harvesting personal information for resale or fraud.
What Organizations Should Do
- Enforce phishing-resistant multi-factor authentication. Move away from SMS and push-approval MFA toward FIDO2 or hardware security keys to neutralize credential theft and MFA-fatigue attacks.
- Monitor cloud identity activity. Deploy alerting for anomalous Microsoft 365 sign-ins, impossible-travel events, unusual mass file downloads, and access from new devices or locations.
- Apply least-privilege access to file stores. Limit which employees can reach repositories containing Social Security numbers and government IDs, and segment sensitive data away from general-purpose accounts.
- Minimize and encrypt sensitive data at rest. Avoid retaining driver's license and Social Security numbers in everyday file shares, and encrypt the records that must be kept.
- Tune data-loss prevention and exfiltration controls. Use DLP policies to flag and block bulk downloads of files containing regulated personal data.
- Rehearse incident response and scoping. Maintain logging that lets investigators rapidly determine which files an attacker accessed, shortening the gap between detection and victim notification.
Sources: Delaware North Data Breach Disclosed; Attorneys Investigating