The Business Council of New York State said the data security incident it suffered earlier this year compromised the sensitive personal data of nearly 50,000 individuals.
Headquartered in Albany, New York, BCNYS is the state’s largest employer association with over 3,000 member organisations, including chambers of commerce, professional and trade associations, and other local and regional business organisations.
In a data security incident notice filed with the Office of Maine Attorney General, BCNYS said that on August 4, it identified unauthorised access within its internal network. The business association immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.
It also took steps to secure the affected network and notified relevant law enforcement authorities about the incident.
“BCNYS learned that an unauthorised party gained access to a limited number of internal systems from approximately February 24, 2025 to February 25, 2025,” BCNYS said.
The compromised data included names, Social Security numbers, dates of birth, state identification numbers, financial institution names, financial account and routing number information, payment card numbers, payment card access PINs, payment card expiration dates, taxpayer identification numbers, electronic signature information, medical provider names, medical diagnosis or condition information, prescription information, medical treatment or procedure information, and health insurance information.
The filing with the Maine state regulator also states that BCNYS has identified at least 47,329 individuals impacted by the incident.
While BCNYS found no evidence of the compromise data being misused, it has advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and the state attorney general.
It has also offered one year of complimentary identity protection and credit monitoring services through IDX to all affected individuals.
At the time of publishing, no known hacker group claimed responsibility for the cyber attack on BCNYS. The organisation also did not share details on who was behind the attack, how much data was compromised, or whether it has received a ransom demand.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543