LeakNet Claims 11 TB of NYC Health + Hospitals Data Stolen, Exposing Over 12 Million Patients
What Happened — LeakNet announced that it exfiltrated roughly 11 TB of data from New York City Health + Hospitals (NYC H+H). The stolen files contain medical, financial and biometric records tied to more than 12 million individuals.
Why It Matters for Compliance & Audit Readiness
- The incident is a textbook example of a data‑exfiltration breach that SOC 2’s CC5.2 (Privacy) controls are designed to prevent and document.
- Continuous evidence of consent management, data‑subject request (DSAR) processes, and privacy‑impact assessments is essential to demonstrate readiness after a large‑scale exposure.
- Verisq’s CookiePLUS privacy suite can provide the audit‑ready artifacts (consent logs, DSAR tracking) needed to satisfy both SOC 2 and emerging privacy regulations (GDPR, CCPA).
Who Is Affected — Large public‑sector health systems, their patients, and any downstream service providers that handle the exposed records.
Recommended Actions
- Immediately verify the scope of the breach against your data‑inventory and map any exposed data elements to SOC 2 CC5.2 controls.
- Collect and preserve consent records, audit logs, and DSAR handling evidence to demonstrate a defensible privacy posture.
- Review and tighten data‑handling policies, especially around biometric and financial information, and conduct a privacy impact assessment.
Source: HackRead
Technical Notes — LeakNet did not disclose the specific attack vector; the breach appears to be a large‑scale data exfiltration of stored records. No CVE or vulnerability was identified. The data includes PHI, PII, financial details and biometric identifiers. Source: HackRead