If you were affected, free legal review is available — no obligation.
Learn how to participate in the class action and what compensation you may be entitled to.
Join the Class Action →Use our verification tool to confirm your letter matches this official AG filing.
Verify My Notice LetterThis case file references a public filing made with the state filing in IN. This website is not affiliated with, endorsed by, or operated by any state government agency.
The Mint Gaming Hall was the subject of a data breach notification filed with the IN Attorney General. The AG filing was recorded on July 14, 2026. The breach or discovery date reported in the filing is June 6, 2026.
From the AG filing description
7The Mint Gaming Hall operates within the highly regulated entertainment, hospitality, and gaming sector, offering patrons gaming experiences, dining, and resort-style amenities. To facilitate these operations, manage loyalty programs, process financial transactions, and comply with strict state and federal gaming regulations, the facility routinely collects and retains a vast amount of sensitive personal and financial data from its customers, employees, and business partners. This repository of high-value information makes the establishment an attractive target for malicious cyber actors seeking to exploit vulnerabilities in commercial networks. In 2026, 7The Mint Gaming Hall reported a significant data security incident to the Indiana Attorney General, triggering widespread concern among affected individuals. While specific attack vectors in such gaming and hospitality breaches frequently involve sophisticated ransomware deployments, credential harvesting, or unauthorized intrusions into third-party vendor databases, incidents of this scale typically highlight systemic vulnerabilities in network defenses. Attackers often target legacy infrastructure, poorly secured point-of-sale systems, or centralized customer management databases where personal identifiable information is consolidated. The exposure resulting from this breach compromises several categories of sensitive data, each carrying distinct and severe risks for victims. Unauthorized access to full names, dates of birth, Social Security numbers, and state-issued identification numbers creates an immediate and long-term danger of identity theft and fraudulent credit applications. Furthermore, because gaming establishments frequently process high-volume financial transactions, the potential compromise of banking details, credit card numbers, and loyalty account credentials exposes victims to unauthorized fund transfers, account takeover, and financial fraud that can take months or years to untangle. As a commercial entity handling sensitive consumer and employee information, 7The Mint Gaming Hall was legally obligated under state data protection statutes and the broader framework of the Federal Trade Commission Act to implement and maintain reasonable cybersecurity measures. These statutory requirements mandate robust encryption standards, proactive vulnerability monitoring, and secure data storage practices. The occurrence of a breach capable of extracting deep personal data strongly suggests a failure in these fundamental security obligations, potentially exposing the organization to significant legal liability for negligence and inadequate data protection. Receiving a formal data breach notification letter from 7The Mint Gaming Hall is more than a warning; it serves as a legal acknowledgment that your private information was compromised due to corporate security failures. Under modern class action jurisprudence, affected individuals have legal standing to pursue compensation and demand stronger accountability without needing to demonstrate immediate out-of-pocket financial loss. Our law firm is actively investigating this breach to protect consumer rights, operating on a contingency fee basis, which means you pay nothing unless we successfully recover compensation on your behalf.
Under the Indiana data breach notification law, you may have a legal claim against The Mint Gaming Hall if any of the following apply:
Based on the data types reported in this filing:
Your SSN is the master key to your identity. Once exposed, criminals can open new lines of credit, take out loans, or file taxes in your name.
Combined with a name and other leaked data, date of birth helps criminals pass identity verification questions at banks and government agencies.
Phone numbers exposed in breaches are used for SIM swapping attacks — hijacking your number to bypass two-factor authentication on financial accounts.
Common categories of compensation in data breach class actions
Courts recognize that the time spent monitoring accounts, placing credit freezes, and dealing with the aftermath of a breach has real economic value. This category of damages is recoverable even without direct financial loss.
Professional credit monitoring services cost $10–$40 per month. Identity theft restoration services, if needed, can cost hundreds of hours and thousands of dollars. Courts have awarded these costs as direct damages in SSN breach cases.
Direct financial losses resulting from the breach — unauthorized charges, fraudulent transfers, or fees incurred through fraud — are recoverable as compensatory damages. Banks may reverse some charges; a class action recovers the remainder and associated costs.
When login credentials are exposed, the costs of downstream account compromises — password managers, security audits, and recovery costs for hijacked downstream accounts — can be recovered. Courts in recent class actions have awarded damages for credential exposure even without proven misuse.
Data breach victims regularly report anxiety, loss of sleep, and ongoing fear of identity theft. These non-economic harms are cognizable injuries in data breach litigation, particularly in cases involving SSN or medical record exposure.
Note: an attorney general breach filing does not by itself establish a settlement fund, a payment amount, or a claim deadline. If an official settlement notice is later issued, rely on that notice for payment details and deadlines.
No. Under Indiana data breach notification law and federal law, the unauthorized exposure of your personal data — regardless of whether it has been actively misused — can be sufficient grounds for a claim. The breach itself is the injury.
Nothing. The Law Office of David S. Harris handles data breach cases on contingency — you pay zero upfront and owe nothing unless compensation is recovered.
Immediately place a free credit freeze at all three bureaus (Equifax, Experian, TransUnion). A freeze blocks new accounts from being opened in your name. Then file a complaint with the FTC at IdentityTheft.gov and contact our office — SSN exposure is one of the most serious breach types.
Banks may reverse fraudulent charges, but they are not obligated to compensate you for time lost, stress, or indirect damages. A class action claim against the breached company can recover those additional categories of harm.
State statutes of limitations for data breach claims typically run 2–4 years from the date of the breach or its discovery. Because this breach was recently disclosed, the window is open — but acting early preserves your options and strengthens the case.
Accepting free credit monitoring from The Mint Gaming Hall does not waive your right to pursue legal action unless you signed a specific release waiving claims. In most cases, victims who accepted monitoring can still file.
Not necessarily. Many data breach victims are never notified directly. If your personal information was held by The Mint Gaming Hall during the relevant period, you may still qualify even without receiving a letter. A free eligibility review can confirm your status.
Applicable State Law
This breach was reported under the Indiana data breach notification law, which mandates notification and establishes your right to seek damages.
The Mint Gaming Hall breach?
Free case review · No fee unless you win