What Happened?
On May 30, 2025, the CSEA NY discovered suspicious activity on its computer systems. Upon detection, CSEA NY launched an internal investigation with the support of leading cybersecurity professionals to determine the nature and scope of the event.
The investigation confirmed that unauthorized access to CSEA NY’s systems occurred between May 3 and May 31, 2025. During this period, an unauthorized party obtained files containing sensitive member information. CSEA NY immediately responded by taking systems offline, changing passwords, deploying security software, restoring systems from backups, and analyzing the compromised files to identify impacted individuals.
On January 20, 2026, CSEA NY reported the incident to the Maine Attorney General. The following day, similar notifications were made to the Vermont Attorney General and the Massachusetts Office of Consumer Affairs and Business Regulation.