NYSEG and RG&E disclosed that an employee of a third-party software consulting firm allowed unauthorized access to customer information systems on January 5, 2012. The breach exposed Social Security numbers, dates of birth, and some financial account numbers. The company engaged forensic experts, consulted law enforcement, and offered credit monitoring to affected customers.