breach
Centers Laboratory breach: 540,000 patient records taken in 6 days
2026-07-14

Centers Laboratory, a New Jersey diagnostics firm that runs testing for healthcare providers, has told US regulators that a breach it spotted in August affects 542,377 people. Attackers were inside the network from 9 to 14 August 2025. The company calls it "limited access", which is a generous read of the situation.
What was taken is not limited in any meaningful sense. Names, dates of birth, Social Security numbers, driver's licence and state ID numbers, passport numbers, health insurance details and medical information. That is the full identity-fraud starter pack, and it keeps its value for years.
Six days, 720 GB
The group claiming the job is WorldLeaks, which is what's left of the Hunters International ransomware crew after a 2025 rebrand. When they relaunched they threw out the file-encrypting malware entirely and went pure extortion. Steal the data, threaten to publish, demand payment. In October they listed Centers Laboratory on their leak site along with roughly 1.6 million files, about 720 GB in total. More than 170 organisations sit on that same site now, Nike and Dell among them.
Six days of access. Three-quarters of a terabyte out the door. That is a lot of data to move without anyone noticing, and it's worth asking what "limited" means when the answer is "they took everything they wanted".
Why dropping the ransomware matters
The shift away from encryption is the part of this story that deserves attention. For years the ransomware playbook was loud on purpose. Encrypt the servers, kill the business until leadership signs off on a payment. The pain was the leverage.
Extortion-only crews have removed the loud bit. There is no locked server to force a board meeting. No downtime that makes IT phone the CEO at 2am. The first anyone outside the attacker knows is often when the leak site listing goes live, or, as in this case, when a notification letter turns up in the mail months later.
A few consequences follow from that:
- Detection is now the whole game. If nothing breaks, nothing tells you to look. Unusual outbound traffic, weird service account behaviour, a server suddenly talking to a cloud storage provider it has never talked to before, that is the signal.
- The window closes fast. Six days was enough here. In other WorldLeaks incidents it has been shorter.
- The regulatory clock is unforgiving. Once a US healthcare provider knows patient data is gone, HIPAA notification timelines kick in whether or not the picture is complete.
The human layer
The initial access vector has not been made public, which is normal for a case still working its way through disclosure. WorldLeaks and its Hunters International predecessor have historically leaned on phishing, credential theft and exposed remote-access services. None of those require anything clever. They require someone to click, reuse a password, or leave a port open.
That is why the shift to quiet extortion changes the calculus for the people who work at places like Centers Laboratory. When the attack does not announce itself, the staff who notice the odd email, the strange login prompt, the unusual request from "IT", become the earliest possible warning. Not the only defence, but often the first one that fires.
Half a million people are now waiting to see what happens with their records. Somewhere on WorldLeaks' site, a countdown is running.