Centers Laboratory Data Breach Affects 540,000 Individuals

A massive data breach at healthcare diagnostics company Centers Laboratory (Centers Lab NJ LLC) has compromised sensitive information of over 540,000 individuals. The breach, which was discovered nearly a year ago in August 2025, is a stark reminder that even seemingly secure organizations can be vulnerable to cyber threats.

The incident occurred when threat actors from the WorldLeaks cybercrime group gained “limited access” to Centers Laboratory systems between August 9 and August 14. During this time, they exfiltrated personal and protected health information (PHI) of patients, including names, dates of birth, Social Security numbers, driver’s license or state identification numbers, passport numbers, and medical records.

The scope of the breach is staggering, affecting 542,377 individuals as revealed by the Department of Health and Human Services’ healthcare data breach tracker. The WorldLeaks group, which emerged in 2025 following the shutdown of the Hunters International ransomware group, has been linked to numerous high-profile attacks on major companies such as Nike and Dell.

What’s particularly disturbing about this incident is that the hackers did not use file-encrypting malware to hold data for ransom. Instead, they focused on stealing sensitive information and extorting money from organizations. This new approach suggests a shift in tactics by cybercriminals, who are adapting to changing security measures and exploiting vulnerabilities that were previously unknown.

Centers Laboratory’s data breach is just one of many high-profile incidents that have highlighted the vulnerability of healthcare systems to cyber attacks. In recent months, numerous organizations, including Medtronic and Accenture, have reported significant data breaches affecting millions of individuals.

The takeaway from this incident is clear: even with robust security measures in place, no organization is immune to the threat of a data breach. As we continue to rely on digital systems for our most sensitive information, it’s essential that we stay vigilant and invest in robust cybersecurity defenses. Patients, healthcare providers, and organizations must work together to ensure that PHI remains protected from cyber threats.

In practical terms, this means staying informed about emerging threats, implementing robust security protocols, and regularly updating software and systems to prevent vulnerabilities. It also requires a collective effort to promote awareness and education on cybersecurity best practices, ensuring that all stakeholders are equipped to protect sensitive information in the digital age.


Source: SecurityWeek — 2026-07-13