June–July 2026: New Jersey diagnostics firm Centers Laboratory (Centers Lab NJ LLC) told regulators and patients that a cybersecurity incident discovered in August 2025 affects 542,377 individuals—one of the largest HIPAA-scale healthcare disclosures of mid-2026. Nearly a year after the intrusion, the WorldLeaks extortion group published a 720 GB archive allegedly stolen from the lab, turning a quiet forensic timeline into a public leak-site spectacle.
What Centers Laboratory confirmed
Per the company's substitute breach notice and SecurityWeek reporting citing HHS OCR data:
- Discovery: Suspicious IT activity on August 25, 2025
- Access window: Unauthorized actor had limited access August 9–14, 2025 and copied data
- Victims: 542,377 individuals on the HHS breach portal
- Notification: State AG filings and customer notices rolled out in June 2026
Centers Laboratory provides testing and laboratory services to healthcare providers from Cedar Knolls, New Jersey. This is not a retail loyalty-card leak—it is full-spectrum protected health information tied to diagnostic workflows.
What data was exposed
The company states impacted systems held names plus one or more of the following—not every field for every person:
- Date of birth
- Social Security number
- Driver's license or state identification number
- Passport number
- Health insurance information
- Medical information
That combination is among the worst menus in healthcare breach law: government IDs plus clinical context. Fraud crews do not need your diagnosis to monetize a row—they need SSN + DOB + insurer name to file phantom claims or impersonate you on explanation-of-benefits calls.
WorldLeaks and the 720 GB dump
Trade press and breach trackers report the WorldLeaks cybercrime group listed Centers Laboratory in October 2025—weeks after the company detected the intrusion but months before public victim notifications completed. WorldLeaks emerged in 2025 after the Hunters International ransomware operation shut down; the rebrand shifted toward data theft and extortion without file-encrypting malware, following the same playbook that hit brands like Nike and Dell in parallel campaigns.
SecurityWeek reported the actors later leaked more than 1.6 million files totaling 720 GB, allegedly including patient test records, laboratory reports, employee information, and internal operational files. The company's verified notice does not dispute WorldLeaks' involvement in marketing the data; it documents the forensic access window and the PHI categories at issue.
The ten-month gap between August 2025 discovery and June 2026 mass notification is the story patients feel in their inbox: long internal data reviews, third-party validation, and state-by-state filing before letters ship—while extortion sites may have been trading samples in the meantime.
Why this breach ranks high on the 2026 calendar
At 542,377 individuals, Centers Laboratory sits in the same tier as major regional health-system disclosures—not a single-clinic ransomware stub. Healthcare diagnostics vendors hold data for many provider clients; one lab compromise can ripple across unrelated physician practices whose patients never heard the Centers Lab brand until the notice arrived.
WorldLeaks' 720 GB publication also signals that encryption-free extortion groups still achieve healthcare-scale exfiltration. No ransom note on encrypted servers does not mean no data left the building.
What was not stated
Centers Laboratory's public notice focuses on copied data categories, not payment card numbers or unrelated consumer retail accounts. The company said it implemented additional safeguards after the event and had not delayed notification due to law enforcement at the time of the substitute notice.
What patients should do
- Read your notification letter for which data types apply to you—not everyone gets every field.
- Place a credit freeze or extended fraud alert if your SSN or government ID was involved.
- Monitor explanation of benefits (EOB) statements from your insurer for lab tests you did not receive.
- Call the dedicated line Centers set up: 1-833-502-8681 (per company notice).
- Ignore download links from leak sites or Telegram channels claiming the full 720 GB archive—archives may contain malware.
- Report suspected medical identity theft to your insurer and IdentityTheft.gov.
Canonical record
Centers Laboratory 2026 breach on BreachHistory.
Sources: Centers Laboratory notice, SecurityWeek, HHS OCR breach portal.