Centers Laboratory (Centers Lab NJ LLC) has alerted the U.S. government that a cyber‑attack in August 2025 compromised the personal and health information of more than 540,000 people. The WorldLeaks extortion group claims to have stolen 720 GB of data and is threatening to publish it.
Key Takeaways
- WorldLeaks accessed Centers Laboratory systems in early August 2025, exfiltrating data of 540,000+ individuals
- Approximately 720 GB of files (1.6 million documents) were leaked by the hackers
- The breach underscores urgent need for stronger healthcare data‑security regulations and breach‑response plans
Centers Laboratory (Centers Lab NJ LLC), a New Jersey‑based health‑diagnostics provider, officially disclosed that a breach discovered nearly a year ago has exposed the personal and protected health information (PHI) of more than 540,000 individuals. The Department of Health and Human Services’ healthcare data breach tracker now lists 542,377 affected records, confirming the scale of the incident.
Timeline and Technical Details
The company’s breach notice, posted on its website, states that threat actors gained “limited access” to its IT environment between August 9 and August 14, 2025. During that window they extracted names, dates of birth, Social Security numbers, driver’s license or state ID numbers, passport numbers, as well as health‑insurance and medical information. Such data is a gold mine for identity theft, insurance fraud, and even black‑mail schemes targeting patients.
Who Is WorldLeaks?
WorldLeaks, a cyber‑crime collective that surfaced in 2025 after the shutdown of the Hunters International ransomware gang, listed Centers Laboratory on its public “target list” in October 2025. Previously known for extorting large corporations like Nike and Dell, the group has shifted from encrypting ransomware to pure data theft and extortion. According to their own claims, they leaked more than 1.6 million files, totaling 720 GB, from the laboratory’s systems.
Implications for the Healthcare Sector
Compromise of health‑care data carries consequences beyond individual privacy. It can disrupt patient care, inflate insurance premiums, and erode public trust in health‑service providers. Industry analysts predict that regulators will tighten enforcement of HIPAA and related state privacy statutes, demanding more robust encryption, multi‑factor authentication, and continuous monitoring of privileged access.
Response and Recommendations
Centers Laboratory has pledged to notify all affected individuals, provide free credit‑monitoring services, and accelerate its cybersecurity roadmap. The plan includes deploying zero‑trust network architecture, expanding endpoint detection and response (EDR) capabilities, and conducting regular penetration testing. Security experts advise all health‑care entities to adopt similar measures, invest in employee phishing awareness training, and maintain an incident‑response playbook that can be activated within hours of detection.