SEIU Local 32BJ disclosed a phishing incident occurring November 13-14, 2017, where an employee's email account was compromised via an externally-hosted email management system. The breach exposed members' full names and Social Security numbers. The union engaged external cybersecurity experts, enhanced security protocols (MFA, password updates), and offered one year of free credit monitoring via Experian IdentityWorks to affected individuals. Notification letters were sent on May 24, 2018.