In February 2026, TWU Local 100, the New York City chapter of the Transport Workers Union of America, was reportedly targeted by the Qilin ransomware gang. The Qilin gang listed the union on its dark web leak site, claiming to have exfiltrated sensitive data. As of the latest reports, there has been no official confirmation, breach notification letters, state Attorney General filings, or statements from TWU Local 100 or authorities.
The types of data reportedly targeted by Qilin may include personally identifiable information such as contact details, job titles, and salaries. Union systems are also reported to retain benefits data, including medical/insurance information, retirement/pensions, housing assistance, childcare, and widows/orphans funding, as well as safety/health records, grievances, disciplinary actions, and union scholarships. The total number of affected individuals may be around 67,000, including approximately 41,000 active workers and 26,000 retirees, primarily NYC transit workers. It remains unclear if Social Security Numbers, confirmed medical records, or specific financial data beyond pensions/salaries were involved.
Details about the full scope and impact of this incident may emerge over time, and official notices can sometimes be delayed.