National Amusements, the Massachusetts-based theater operator and former controlling shareholder of Paramount Global, paid $250,000 to New York State in November 2024 to resolve the National Amusements data breach settlement with the state Attorney General over a 2022 hack that exposed personal information of 82,128 employees and contractors. The money went to New York, not to affected workers. A separate employee class action seeking compensation for individuals was dismissed in March 2025.1NY Attorney General. Attorney General James Secures $250,000 From Movie Theater Operator for Failing to Protect Employee Data2Bloomberg Law. National Amusements Beats Worker Data Breach Suit Over Standing
What the $250,000 Settlement Covers
Attorney General Letitia James announced the agreement, formally an Assurance of Discontinuance, on November 15, 2024. The $250,000 payment combines penalties, disgorgement, and costs, and it goes to the State of New York. The settlement does not create a restitution fund for employees, though it preserves their right to pursue private claims.3NY Attorney General. National Amusements Assurance of Discontinuance
Alongside the payment, National Amusements agreed to overhaul its security practices:
- Develop and implement a comprehensive information security program within 90 days, including risk assessments, documented safeguards, and employee training.
- Complete a full inventory of the personal information it holds within 180 days.
- Encrypt personal information in storage and transit, enforce complex password rules, and require multifactor authentication for administrative and remote access.
- Maintain a written incident response plan covering investigation and consumer notification.
- Undergo an independent security assessment within one year, then annual assessments for five more years.
What Affected Employees Actually Received
The remedies delivered directly to workers came through National Amusements’ notification letters, not through the state settlement. The company offered, at no cost:
- Complimentary Experian IdentityWorks credit monitoring with reports across all three major credit bureaus.
- Access to Experian identity restoration specialists who could investigate fraud, place credit freezes, and contact government agencies on a victim’s behalf.
- A $1 million identity theft insurance policy underwritten by American Bankers Insurance Company of Florida, covering certain costs and unauthorized electronic fund transfers.
Enrollment ran through a dedicated Experian site and closed on March 15, 2024. No credit card was required.4Montana DOJ. National Amusements Consumer Notification Letter
The Employee Class Action Was Dismissed
Two former employees, Nathan Harvey and Nick Deprospo, filed a proposed class action in January 2024 in the U.S. District Court for the District of Massachusetts, naming the company under its Showcase Cinemas brand. The case, Harvey v. National Amusements, Inc., No. 1:24-cv-10027, brought claims for negligence, breach of implied contract, unjust enrichment, and invasion of privacy. A negligence per se claim was voluntarily dropped.5Mass Lawyers Weekly. Harvey v. National Amusements, Inc., No. 1:24-cv-10027-GAO
On March 27, 2025, Judge George A. O’Toole Jr. dismissed the case for lack of standing. The court found the plaintiffs had not shown that their claimed injuries were traceable to the 2022 breach. One plaintiff cited unauthorized credit card charges, but Judge O’Toole ruled the evidence was insufficient to link them to the incident. No class settlement was reached or approved.2Bloomberg Law. National Amusements Beats Worker Data Breach Suit Over Standing
For employees whose data was exposed, that ruling means there is no pending class case to file a claim against. Individual legal action remains possible under the state settlement’s terms.3NY Attorney General. National Amusements Assurance of Discontinuance
What Was Stolen and Who Was Affected
Between December 13 and December 15, 2022, a hacker used stolen employee credentials to break into the company’s systems. Multifactor authentication existed but was not enforced across all access channels, giving the attacker an opening.1NY Attorney General. Attorney General James Secures $250,000 From Movie Theater Operator for Failing to Protect Employee Data
The breach exposed data for 82,128 current and former employees and contractors, including 23,365 New York residents and 64 Maine residents. Compromised information included names, dates of birth, Social Security numbers, passport numbers, financial account numbers, driver’s license numbers, and health insurance account numbers. Moviegoers were not affected; the intrusion was limited to employee and contractor records.1NY Attorney General. Attorney General James Secures $250,000 From Movie Theater Operator for Failing to Protect Employee Data6Deadline. National Amusements Maine AG Breach Notification
Why New York Penalized the Company
A vendor flagged suspicious activity and possible malware in December 2022, but National Amusements did not confirm the full scope of the intrusion until August 23, 2023.7Deadline. Paramount CBS Owner National Amusements Cyberattack Individual notifications did not begin until December 22, 2023, more than a year after the breach and roughly four months after the company confirmed what had been taken.6Deadline. National Amusements Maine AG Breach Notification The New York Attorney General found that delay violated the state’s SHIELD Act, which requires notification within a reasonable timeframe, and that the underlying cybersecurity controls were inadequate.1NY Attorney General. Attorney General James Secures $250,000 From Movie Theater Operator for Failing to Protect Employee Data