CSIDB logo
Incident

Co-op City

Incident posture

Attack window
May 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-09 11:05

Linked entities

Victim
Co-op City
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Apr 2025
Discovered
May 2025
Disclosed
Jun 2025
Resolved
Pending

Summary

Riverbay detected unusual activity in its IT network, promptly isolated the affected systems, and engaged a third‑party cybersecurity firm while notifying law enforcement. The investigation revealed that an unauthorized party had accessed the network over a period of several weeks and may have obtained files containing names, Social Security numbers, and bank account details of shareholders, applicants, current and former employees, and possibly residents whose information was shared by shareholders. The company subsequently notified potentially affected individuals, provided complimentary credit monitoring services, and established a toll‑free incident response line. To prevent recurrence, it added security controls and conducted additional employee training on data security.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On May 21, 2025, Riverbay Corporation identified unusual activity in its information technology network. Upon detection, the company immediately isolated and secured the affected systems. Riverbay then launched an investigation with the assistance of a third‑party cybersecurity firm and notified law enforcement. The investigation determined that an unauthorized party gained access to the IT network and systems between April 21, 2025 and May 21, 2025. On June 2, 2025, Riverbay concluded that the unauthorized party had accessed and/or acquired files from certain computer systems.

The investigation could not rule out that the accessed files might contain information pertaining to Co‑op City shareholders and applicants, as well as current and former Riverbay employees. It also noted that resident information could be involved if it had been provided to Riverbay by a shareholder. The types of data potentially involved include names, Social Security numbers, and bank account and routing numbers. On June 20, 2025, Riverbay began notifying individuals whose information may have been involved in the incident. As part of the response, the company established a dedicated toll‑free incident response line and offered complimentary credit‑monitoring memberships to potentially affected individuals. Riverbay also implemented additional security measures to enhance network security and provided further data‑security training for employees.

The notification process included providing a contact number (1‑866‑461‑1672) available Monday through Friday, 9:00 a.m. to 6:30 p.m. Eastern Time, excluding major U.S. holidays. Riverbay stated that it would continue to monitor the situation and cooperate with law enforcement. The company indicated that it had taken steps to address the incident and to strengthen its security posture.

Sources

Sources available to members: 1 source.

CSIDB