The Business Council of New York State
bd_a8a0bd8c59db3d63 · schema v1 · pii pii-v1
Full breach record for The Business Council of New York State →The Business Council of New York State, Inc. (BCNYS) notified the New Hampshire Attorney General on August 21, 2025, of a cybersecurity incident occurring February 24-25, 2025. BCNYS discovered unauthorized access to internal systems on February 28, 2025. The incident affected 65 New Hampshire residents, exposing names, dates of birth, Social Security numbers, and medical/clinical information. BCNYS engaged third-party forensic experts, contained the incident, and is offering complimentary credit monitoring to affected individuals. No identity fraud has been reported to date.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 24, 2025
Begins
Feb 28, 2025
Discovered
Aug 21, 2025
Filed
vs. sector median
+7 wks slower
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Massachusetts State AGbd_1b618bfecdc5a2102025-08-16 · +5dVerified
- Nebraska State AGbd_36a20dde9a550d2a2025-08-15 · +6dVerified
- Indiana State AGbd_5861f2c97a5fa1ee2025-08-15 · +6dCandidate
- Maine State AGbd_fe52c70c81b3bd852025-08-15 · +6dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Pattern: first filing Aug 15 (NE), last Aug 21 (NH) — a 6-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.