What Happened in the New York City Regional Center Data Breach?
New York City Regional Center, LLC, known as NYCRC, began sending breach notification letters to affected individuals in August 2026. The firm operates as a USCIS-designated regional center under the federal EB-5 Immigrant Investor Program. It has channeled more than $1.5 billion in foreign investment capital into New York real estate projects, including studio and production facilities.
According to a notice filed with the Massachusetts Attorney General’s Office, NYCRC identified a cybersecurity incident that may have allowed unauthorized access to personal information. The filing does not describe how the intrusion happened. It also does not state when the incident occurred or when NYCRC first discovered it, since Massachusetts law limits how much detail a company can include in these public notices.
Because the underlying timeline remains undisclosed, the only confirmed date tied to this event is the filing period. NYCRC submitted its notification letters in early August 2026. Consequently, this report reflects the most recent public information available, and it will be updated if NYCRC releases further details about when the breach actually began.
Handling an incident like this typically requires a lengthy forensic process. Investigators must determine the scope of unauthorized access, identify every affected person, and coordinate with a response vendor. In this case, NYCRC engaged Kroll to manage notification support and credit monitoring enrollment for impacted individuals.
Who was affected?
The individuals affected appear to be clients and investors who submitted applications through NYCRC’s EB-5 program. Because this program requires detailed financial and immigration paperwork, the pool of affected people likely includes foreign nationals seeking U.S. residency through investment, along with any associated family members listed on those applications.
NYCRC has not disclosed a specific number of affected individuals nationwide. The notification letter filed with Massachusetts regulators covers only residents of that state, so the true scope of the breach may be considerably larger. As a result, individuals who have not yet received a letter should not assume they are unaffected.
What Information Was Potentially Exposed?
NYCRC has not publicly confirmed which specific categories of personal data were involved for the general population of recipients. However, the nature of the EB-5 application process gives a strong indication of what may be at risk, since investors must submit extensive documentation to prove their funds and identity.
- Full names
- Social Security numbers
- Financial account information
- Immigration-related identification documents
Given the type of paperwork investors submit during the application process, exposed data could include highly sensitive financial records. Because EB-5 applicants must prove the lawful source of large sums of money, their files often contain bank statements, tax records, and government-issued identification numbers.
This combination of data creates a heightened risk of identity theft. Criminals who obtain Social Security numbers alongside financial account details can open new credit lines, file fraudulent tax returns, or attempt to redirect investment funds. Because EB-5 investors often move large sums internationally, fraudsters may also try to intercept future wire transfers using stolen identity information.
In addition to financial fraud, exposed immigration documents carry their own risks. Someone with access to identification records could attempt to impersonate a victim in immigration proceedings or use the documents to support fraudulent applications elsewhere. Therefore, affected individuals should treat this incident as a serious threat to both their finances and their legal identity.
What is the company doing?
NYCRC says it identified the cybersecurity incident and responded by notifying regulators and affected individuals. The company filed formal notice with the Massachusetts Attorney General’s Office as part of its legal obligations under state breach notification laws.
To help reduce harm, NYCRC is offering two years of complimentary credit monitoring, fraud consultation, and identity theft restoration services through Kroll. This support gives affected individuals a way to detect suspicious activity early. However, because the monitoring period is limited, individuals should plan to stay alert well beyond the two-year window Kroll provides.
What Should Affected Individuals Do?
Enroll in the Free Credit Monitoring Offered
If you received a letter from NYCRC, activate the Kroll credit monitoring services as soon as possible. These services can alert you quickly if someone attempts to open new credit accounts using your information.
Be sure to enroll before any stated deadline in your letter, since delaying could cause you to lose access to the free service. This step costs nothing and provides an added layer of protection while you monitor your accounts yourself.
Place a Fraud Alert or Credit Freeze
Because Social Security numbers may be involved, consider placing a fraud alert or credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new creditors from accessing your credit file, which makes it much harder for identity thieves to open accounts in your name.
While a freeze requires a few extra steps when you apply for credit yourself, it offers strong protection during a period of heightened risk. Fraud alerts are easier to set up and still require businesses to verify your identity before extending new credit.
Monitor Financial and Investment Accounts Closely
Regularly review your bank, credit card, and investment account statements for unfamiliar charges or withdrawals. Because EB-5 investors often maintain large account balances, even small unauthorized transactions can be an early warning sign of bigger fraud attempts.
If you notice anything unusual, contact your financial institution immediately. Acting quickly can limit your liability and help stop further unauthorized activity before it escalates.
Watch for Phishing Attempts Referencing This Breach
Scammers often use news of a breach to craft convincing phishing emails or phone calls. Be cautious of any message claiming to be from NYCRC or Kroll that asks you to click a link or provide personal details.
Instead, contact NYCRC or Kroll directly using verified contact information from your official notification letter. This helps ensure you are not handing sensitive information to a scammer pretending to help you.
Report Signs of Identity Theft Promptly
If you discover signs of identity theft, report them right away to your local police department and to the Federal Trade Commission through identitytheft.gov. Filing a report creates an official record that can help you dispute fraudulent charges later.
Additionally, consider speaking with a data breach attorney to understand your legal options. An attorney can help you evaluate whether you qualify for compensation tied to this incident and guide you through the claims process.
More Information
Official data breach notification from Oregon Department of Justice
