Jewish Family and Community Services- East Bay (JFCS East Bay) has notified clients that Cerenade, a vendor used by its Immigration Legal team to store case-related documents, was broken into by unauthorized persons on or about October 2, 2025. JFCS East Bay says it was told of the intrusion on October 9, 2025, and that its security team then worked with Cerenade to figure out what happened and who was affected. The organization describes this as a third-party vendor breach rather than a direct hack of its own systems, and notes that Cerenade is widely used across the immigration legal field for case record keeping.
The letter is addressed to clients whose immigration case filing documents were stored in the Cerenade system at the time of the breach. JFCS East Bay has not stated a total number of people affected in the portion of the letter provided, and says its review focused on identifying and notifying those clients believed to be at risk.
What information was exposed?
- Full name
- Date of birth
- Passport number or Social Security number (contained within immigration case filing documents)
JFCS East Bay says clients will receive a separate letter directly from Cerenade explaining its investigation and next steps, which will include one year of free credit monitoring. No enrollment link, activation code, or deadline was included in the JFCS East Bay letter itself, so watch for that follow-up communication from Cerenade for the specific sign-up instructions.
What should you do now?
- Watch for and open the separate letter from Cerenade, which should contain the specific steps and deadline for activating your free year of credit monitoring.
- Because your Social Security number or passport number may have been exposed, consider placing a fraud alert or a security freeze on your credit files with Equifax, Experian, and TransUnion.
- Review your bank, credit card, and any government benefit statements closely for charges or activity you do not recognize.
- Be cautious of unexpected calls, emails, or letters claiming to be from immigration authorities, government agencies, or financial institutions asking you to confirm personal details — scammers sometimes use breach news to impersonate officials.
- Consider signing up for a service like Aura or LifeLock, which can alert you if your information appears elsewhere, such as on the dark web.
- Keep a copy of this notification letter and any follow-up correspondence in case you need to reference it later when disputing fraudulent activity.