NYC Health + Hospitals disclosed that an unauthorized party accessed its systems between about November 25, 2025, and February 11, 2026, after suspicious network activity was detected on February 2, 2026. The public notice said files were copied during the intrusion, which the health system indicated appeared linked to a compromise involving an unnamed third-party vendor. The organization reported the incident to the U.S. Department of Health and Human Services as affecting 1.8 million individuals.
LeakNet has now claimed the breach was far larger, alleging it stole 11TB of data tied to more than 12 million people, including medical, financial, biometric, and personal information. Screenshots published by the group reportedly showed databases, spreadsheets, internal messages, and an alleged directory listing, but those materials do not independently verify the scale of the theft or prove that executives knew of a 12 million-record impact. NYC Health + Hospitals had not publicly addressed LeakNet’s July post at the time of reporting, while congressional scrutiny had already intensified after Senator Bill Cassidy sought answers from CEO Mitchell Katz about the breach and notification process.

See the actors and campaigns active against you right now.
8 events from the most recent confirmed update back to the earliest known activity.
On July 27, 2026, LeakNet published screenshots it said showed databases, spreadsheets, internal messages, and a directory listing from NYC Health + Hospitals. The post accompanied claims that 11TB of data tied to more than 12 million people had been stolen, though the article says those claims were unconfirmed.
In June 2026, Senator Bill Cassidy sent a letter seeking answers from CEO Mitchell Katz about the incident and related notifications. The article says the letter did not accuse the organization of concealing a 12 million-person breach.
NYC Health + Hospitals published a press release titled notice of data breach on March 27, 2026. This was a formal public notice related to the incident.
On March 24, 2026, NYC Health + Hospitals publicly disclosed the breach. The organization said an unauthorized party had accessed systems and copied files.
NYC Health + Hospitals said the unauthorized party had access to systems through about February 11, 2026. During that period, files were copied from affected systems.
The health system detected suspicious network activity on February 2, 2026, which led to the discovery of the incident. The unauthorized access period was later described as continuing into February.
NYC Health + Hospitals said an unauthorized party accessed its systems beginning about November 25, 2025, in an intrusion that later involved file copying. The organization later indicated the activity appeared linked to a breach at an unnamed third-party vendor.
NYC Health + Hospitals reported 1.8 million affected individuals to the U.S. Department of Health and Human Services in connection with the breach. The reference does not provide a specific filing date.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcehackread.com
Open sourcenychealthandhospitals.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.