[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fxlduswciza4x":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":27,"seoTitle":28,"seoTitleEn":29,"seoDescription":28,"seoDescriptionEn":30,"logoUrl":31,"isVerified":4,"isSensitive":4,"isSpamList":32,"isMalware":32,"company":33},"6a6f87d85f72cd7c2b7b28ee","DelawareNorth2026","Delaware North Data Breach","delaware-north-2026","delawarenorth.com","2026-01-27T00:00:00.000Z","2026-08-02T18:09:28.438Z","Unauthorized access to an employee Microsoft account with file copying","https:\u002F\u002Foag.my.site.com\u002Fdatasecuritybreachreport\u002Fapex\u002FDataSecurityReportsPage",[14,16],"https:\u002F\u002Fnashua.inklink.news\u002Fdelaware-north-cyber-attack-affects-more-than-1000-nh-residents\u002F",66352,"known",null,"people","Medium",[23,24,25,26],"Names","Social security numbers","Driver's license numbers","Government IDs","\u003Cp>Delaware North is a United States hospitality and entertainment company that operates hotels, gaming, sports, foodservice, and visitor destinations worldwide. On January 28, 2026, the company detected unusual activity in an employee's Microsoft account, secured the account, and began an investigation.\u003C\u002Fp>\u003Cp>The Texas Attorney General reports 66,352 affected people nationwide, including 976 Texas residents. The separately reported 1,133 New Hampshire and 132 Maine residents are also state subsets within the nationwide figure, not additional totals.\u003C\u002Fp>\u003Ch2>Confirmed timeline\u003C\u002Fh2>\u003Cp>The investigation found that an unauthorized actor copied certain files on January 27. Unusual account activity was detected on January 28, the review identified the personal-information scope on May 28, and notification letters were mailed on June 5.\u003C\u002Fp>\u003Cp>The Texas record lists January 27-28 as the event period and May 28 as the discovery date. Because the company notice identifies January 28 as the initial security detection, the dates are preserved as different stages of the investigation.\u003C\u002Fp>\u003Ch2>What information may have been affected?\u003C\u002Fh2>\u003Cp>Depending on the person, affected information may include names, Social Security numbers, driver's-license numbers, or other state-issued identification numbers. The New Hampshire and Maine notices specifically confirm combinations of names and driver's-license or state-ID information.\u003C\u002Fp>\u003Cp>Not every field should be assumed for every person. The sources do not confirm payment-card data, bank accounts, medical records, passwords, or email contents, so those categories are not added to the incident scope.\u003C\u002Fp>\u003Ch2>Identity-theft risks\u003C\u002Fh2>\u003Cp>A combination of Social Security numbers and government identification can support fraudulent credit applications, tax fraud, or identity-verification abuse. Notice recipients should monitor credit reports and new-account activity.\u003C\u002Fp>\u003Cp>People whose driver's license or state ID was affected can review replacement and fraud-monitoring options with the issuing agency. A credit freeze or fraud alert can make unauthorized account opening more difficult where appropriate.\u003C\u002Fp>\u003Ch2>Fake notice and support messages\u003C\u002Fh2>\u003Cp>Attackers may combine the company name, incident dates, and real identity details in phishing messages about free monitoring enrollment, human resources, travel, or venue services. A genuine breach announcement does not make an unexpected link trustworthy.\u003C\u002Fp>\u003Cp>Independently verify enrollment or information requests and use a previously known official company channel. Do not treat the link, phone number, or reply address in an unexpected message as the verification source.\u003C\u002Fp>\u003Ch2>Practical protective steps\u003C\u002Fh2>\u003Cp>Check the enrollment deadline for Delaware North's complimentary credit and identity-monitoring service, and watch credit reports, tax records, and government-ID use. Report an unfamiliar account or application promptly to the relevant agency and financial institution.\u003C\u002Fp>\u003Cp>The sources do not say that affected individuals' account passwords were exposed. Even so, a unique email password and multifactor authentication help reduce the impact of follow-on phishing that may exploit this incident.\u003C\u002Fp>\u003Ch2>How should a result be interpreted?\u003C\u002Fh2>\u003Cp>\u003Cstrong>A positive match connected to this incident is sufficient reason to review the official notice and apply its protective steps.\u003C\u002Fstrong> It does not, by itself, show that every listed identity field was present for that person.\u003C\u002Fp>\u003Cp>A negative result does not guarantee that no record exists in other Delaware North systems or unrelated breaches. Anyone who received a direct company notice should follow the letter and regulator guidance regardless of a search result.\u003C\u002Fp>","","Delaware North Data Breach (66.4 Thousand People Affected)","Delaware North's January 2026 breach affected 66,352 people, exposing names, Social Security numbers, driver's licenses, and state-issued IDs.","https:\u002F\u002Fwww.delawarenorth.com\u002Fapple-touch-icon.png",false,{"name":34,"sector":35,"country":36,"website":10,"websiteArchiveUrl":28,"websiteStatus":37,"websiteCheckedAt":12},"Delaware North","Hospitality and Entertainment","United States","active"]