SYS::ONLINE
Wasteland.
Briefs1674
Issues21
SinceFeb 2026
LIVE
▣ Breach DELAWARE-NORTH-DAT 2026-06-10

Delaware North: Microsoft Account Compromise and File Exfiltration

"Global hospitality and entertainment company Delaware North has disclosed a data breach that exposed the personal information of individuals after an unauthorized actor compromised an employee's Microsoft account and…"

Global hospitality and entertainment company Delaware North has disclosed a data breach that exposed the personal information of individuals after an unauthorized actor compromised an employee's Microsoft account and stole copies of certain files. The company confirmed the incident in notification letters filed with the New Hampshire and Texas Attorneys General, and began mailing notices to affected individuals on June 5, 2026. The breach is now the subject of a class-action investigation by attorneys working with ClassAction.org.

What Happened

Delaware North identified suspicious activity in an employee's Microsoft account on January 28, 2026. The subsequent investigation determined that an unauthorized actor had accessed the account and stolen copies of certain files the day prior, on January 27. The intrusion window was short, but it was enough time for the attacker to exfiltrate data before the activity was detected.

It took the company roughly four months to complete its review of the affected files. On May 28, 2026, Delaware North determined that the exfiltrated files contained personal information belonging to individuals, and notification letters began going out on June 5. Delaware North operates over 200 hotels, casinos, restaurants, sports venues, and other locations worldwide, giving the company a large pool of employees, guests, and partners whose data it holds.

What Was Taken

Based on regulatory filings, the stolen files may have contained the following categories of personal information:

This combination is highly sensitive. Names paired with Social Security numbers and government-issued ID numbers form a near-complete identity kit, the exact data set that enables synthetic identity fraud, fraudulent credit applications, and tax fraud. Unlike a password, these identifiers cannot simply be reset, which extends the risk window for affected individuals for years.

Why It Matters

The Delaware North incident is a textbook example of how a single compromised cloud identity can lead to a wide-reaching data exposure. The attacker did not need to breach a network perimeter or deploy ransomware; they only needed valid access to one employee's Microsoft account to reach and exfiltrate files containing regulated personal data.

The timeline is also instructive for defenders. The actual theft occurred on January 27, detection followed within a day, but full scoping of the exposed data took until late May. That four-month lag between detection and notification is common in cloud data-theft cases, where reconstructing exactly what an attacker touched is slow and labor intensive. For affected individuals, it means their data was in criminal hands long before they were warned.

The Attack Technique

The breach centered on a compromised Microsoft account belonging to an employee. While Delaware North has not publicly detailed how the credentials were obtained, account compromises of this type are most commonly the result of phishing, credential stuffing using passwords leaked in prior breaches, session-token theft, or social engineering of help-desk staff to bypass multi-factor authentication.

Once inside a Microsoft 365 environment, an attacker with a single set of valid credentials can often reach files stored in OneDrive, SharePoint, and email attachments, then quietly download copies. The fact that the actor stole files rather than deploying disruptive malware suggests a financially motivated data-theft operation focused on harvesting personal information for resale or fraud.

What Organizations Should Do

Sources: Delaware North Data Breach Disclosed; Attorneys Investigating