HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

LeakNet Claims 11 TB of NYC Health + Hospitals Data Stolen, Exposing Over 12 Million Patients

LeakNet announced the theft of roughly 11 TB of records from NYC Health + Hospitals, affecting more than 12 million individuals. The breach highlights gaps in privacy controls and the need for audit‑ready consent and DSAR evidence under SOC 2.

LiveThreat™ Intelligence · 📅 July 30, 2026· 📰 hackread.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
hackread.com

LeakNet Claims 11 TB of NYC Health + Hospitals Data Stolen, Exposing Over 12 Million Patients

What Happened — LeakNet announced that it exfiltrated roughly 11 TB of data from New York City Health + Hospitals (NYC H+H). The stolen files contain medical, financial and biometric records tied to more than 12 million individuals.

Why It Matters for Compliance & Audit Readiness

  • The incident is a textbook example of a data‑exfiltration breach that SOC 2’s CC5.2 (Privacy) controls are designed to prevent and document.
  • Continuous evidence of consent management, data‑subject request (DSAR) processes, and privacy‑impact assessments is essential to demonstrate readiness after a large‑scale exposure.
  • Verisq’s CookiePLUS privacy suite can provide the audit‑ready artifacts (consent logs, DSAR tracking) needed to satisfy both SOC 2 and emerging privacy regulations (GDPR, CCPA).

Who Is Affected — Large public‑sector health systems, their patients, and any downstream service providers that handle the exposed records.

Recommended Actions

  • Immediately verify the scope of the breach against your data‑inventory and map any exposed data elements to SOC 2 CC5.2 controls.
  • Collect and preserve consent records, audit logs, and DSAR handling evidence to demonstrate a defensible privacy posture.
  • Review and tighten data‑handling policies, especially around biometric and financial information, and conduct a privacy impact assessment.

Source: HackRead

Technical Notes — LeakNet did not disclose the specific attack vector; the breach appears to be a large‑scale data exfiltration of stored records. No CVE or vulnerability was identified. The data includes PHI, PII, financial details and biometric identifiers. Source: HackRead

📰 Original Source
https://hackread.com/leaknet-11tb-stolen-nyc-health-hospitals-data-breach/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · PrivacyOps · CookiePLUS

A privacy incident is a question about your consent record.

CookiePLUS and Verisq AI Trust Operations keep consent, DSAR, and data-handling evidence continuously ready — so a data-exposure event finds you prepared, not scrambling.

See how Verisq AI Trust Operations handles privacy →