A data breach at Centers Lab NJ LLC has exposed the personal information of 542,377 people, triggering investigations by two law firms into potential class action lawsuits against the Hanover, New Jersey–based diagnostic testing laboratory. The breach occurred over a six-day window in August 2025 when an unauthorized actor accessed the company’s systems, stealing 720 gigabytes of data comprising approximately 1.6 million files. The exposed records contain highly sensitive information including names, Social Security numbers, dates of birth, driver’s license and passport numbers, health insurance details, and medical records—the kind of comprehensive identity data that can enable financial fraud, medical identity theft, and years of downstream harm. The breach was not discovered until August 25, 2025, nearly two weeks after the unauthorized access ended.
By October 2025, the WorldLeaks extortion group had claimed responsibility and listed Centers Lab among its victims on dark web leak sites, marking a stark escalation in the breach’s public exposure. The 542,000+ figure exceeded the federal threshold that triggers mandatory notification to the U.S. Department of Health and Human Services Office for Civil Rights, placing the breach on the OCR public breach portal. Affected individuals have been offered credit monitoring and identity theft protection services, but the scale of exposure—affecting more than half a million people—makes this one of the larger healthcare data breaches in recent years.
Official resources:
- Enroll in complimentary credit monitoring and identity theft protection — Centers Lab's official breach notice where affected individuals can register for 12–24 months of included credit monitoring and identity theft protection services.
- Contact investigators or submit a claim for the class action — Schubert Jonckheer & Kolbe LLP's investigation page where affected patients can connect with attorneys investigating potential class action claims on their behalf.
Table of Contents
- How Did 542,000 People’s Records Get Exposed in the Centers Lab Breach?
- What Personal Information Was Stolen and Why It Matters for Victims?
- Who Is WorldLeaks and Why Did They Target Centers Lab?
- When Did the Breach Happen, and How Long Before Anyone Noticed?
- What Legal Action Has Been Triggered Against Centers Lab?
- What Protection and Recourse Are Affected Individuals Receiving?
- What Does the Centers Lab Breach Tell Us About Healthcare Data Security?
- Frequently Asked Questions
How Did 542,000 People’s Records Get Exposed in the Centers Lab Breach?
Centers Lab NJ LLC operates as a diagnostic testing laboratory providing medical and laboratory services to healthcare provider clients across the country. On August 9, 2025, an unauthorized actor gained access to the company’s systems without authorization. The intrusion lasted until August 14, 2025—a six-day window during which the attacker methodically extracted data. The scope was enormous: the attacker removed 720 gigabytes of data in the form of approximately 1.6 million individual files. Because Centers Lab handles patient test results and medical records for healthcare providers, the database contained comprehensive personal and health information rather than isolated data points.
The breach went undetected for eleven days. It wasn’t until August 25, 2025, that Centers Lab’s security team identified suspicious activity and initiated an investigation. By that time, the damage was already done—the attacker had complete copies of records for over half a million patients. The discovery delay is common in healthcare breaches; attackers typically work during off-hours or blend into normal network traffic, making detection inherently difficult. Once the breach was identified, Centers Lab followed regulatory requirements and notified affected individuals, regulators, and the media. The company did not publicly disclose how the attacker initially gained access—whether through a vulnerable web application, compromised credentials, or another method—leaving a key question unanswered for patients trying to understand their risk.
What Personal Information Was Stolen and Why It Matters for Victims?
The data compromised in the Centers Lab breach includes some of the most sensitive identifiers in existence. Stolen records contain full names, dates of birth, social security numbers, driver’s license and state ID numbers, passport numbers, health insurance member IDs and policy information, and detailed medical information including test results and diagnoses. This combination of data is particularly dangerous because it contains everything an identity thief needs to open fraudulent accounts, apply for credit, file false tax returns, or commit healthcare fraud. The inclusion of medical information adds a layer of harm beyond financial identity theft.
A bad actor with access to someone’s health records, combined with their name and insurance details, can potentially commit medical identity theft—using someone else’s insurance to receive treatment, obtain prescription medications, or make fraudulent claims. This can result in fraudulent charges appearing on medical bills, incorrect treatment codes being added to someone’s medical history, and disruption of their actual healthcare. Unlike credit card fraud, which typically gets caught within weeks, medical identity theft can go undetected for months or years, and correction requires navigating complex healthcare bureaucracy. The exposure of passport numbers also creates international identity theft risk, potentially enabling someone to assume the victim’s identity for travel or other uses.
Who Is WorldLeaks and Why Did They Target Centers Lab?
Worldleaks is an extortion-as-a-service operation that emerged in January 2025 as a rebranding of the Hunters International ransomware group, which itself is believed to have descended from the earlier Hive ransomware gang. Unlike traditional ransomware gangs that encrypt data and demand ransom for decryption keys, WorldLeaks operates under an extortion-only model—they steal data and threaten to publish it on the dark web unless the victim company pays. This approach has become increasingly common because it avoids the technical challenges of deploying ransomware and sidesteps law enforcement attention sometimes directed at encryption-based attacks.
WorldLeaks claimed responsibility for the Centers Lab breach and followed through on the threat by listing the organization and samples of the stolen data on its dark web leak site in October 2025. The group does not appear to have targeted Centers Lab for any specific reason beyond the vulnerability presented by the organization’s security posture and the potential ransom payment. For WorldLeaks, healthcare organizations are high-value targets: they often face pressure to pay quickly to avoid operational disruption, they handle data that allows targeting patients and insurance companies with downstream fraud, and they typically have insurance that covers extortion payments. Centers Lab’s size and the sensitivity of the data it handled made it an attractive target.
When Did the Breach Happen, and How Long Before Anyone Noticed?
The breach timeline is important for understanding exposure window and why detection mattered. Unauthorized access to Centers Lab’s systems occurred between August 9 and August 14, 2025—a focused six-day intrusion window. The attacker likely conducted reconnaissance before the access period, then executed the data extraction during that week. Discovery did not occur until August 25, 2025, eleven days after the unauthorized access ended. This delay means all 1.6 million files were copied to the attacker’s control before any defensive action could be taken.
The eleven-day detection lag is problematic but not unusual in healthcare breaches. Attackers typically work during nights or weekends to minimize the chance of detection by system administrators. They also often configure access to mimic legitimate backup operations or routine administrative activity, blending into normal network traffic patterns. By the time Centers Lab identified the suspicious activity on August 25, the attacker had already disappeared. The discovery itself triggered investigation, notification processes, and eventual disclosure—but it could not undo the data theft. For affected individuals, this timeline matters because it defines how long their data was in attackers’ hands before the public became aware of the breach.
What Legal Action Has Been Triggered Against Centers Lab?
Two law firms have announced investigations into the Centers Lab breach on behalf of affected individuals. Edelson Lechtzin LLP announced an investigation on July 16, 2026, investigating potential class action claims against Centers Lab over the WorldLeaks attack. The firm is seeking to pursue legal remedies on behalf of affected individuals. Simultaneously, Schubert Jonckheer & Kolbe LLP announced a separate investigation, also pursuing claims on behalf of the 542,377 affected patients.
Both firms are investigating whether Centers Lab failed to implement adequate security measures to protect patient data, whether the company’s response to the breach was timely and appropriate, and whether the company should be held liable for the harm caused to affected individuals. As of the breach announcements, class action lawsuits have not yet been formally filed—the law firms are still in the investigation phase, evaluating whether sufficient evidence and damages exist to proceed. This is a common pattern in data breach class actions. The investigations typically examine whether the company’s security practices fell below industry standards, whether similar breaches at competitors were prevented through better security, whether the company ignored warnings about known vulnerabilities, and what actual harm affected individuals have experienced (unauthorized account openings, fraudulent charges, credit monitoring costs, time spent resolving identity theft). The investigations take weeks or months before law firms decide whether to file formal litigation.
What Protection and Recourse Are Affected Individuals Receiving?
Centers Lab has offered affected individuals complementary credit monitoring and identity theft protection services for 12 to 24 months. This is a standard response in large healthcare breaches, though the value of such services varies. Credit monitoring can alert individuals to new credit inquiries or accounts opened in their names, giving them a chance to dispute fraudulent activity before it causes extensive damage. Identity theft protection typically includes monitoring for unauthorized use of Social Security numbers, alerts to changes in credit reports, and assistance contacting creditors or financial institutions if fraud is detected. However, these protections have meaningful limitations.
The services are typically provided by third-party monitoring companies, not by Centers Lab itself, and their effectiveness depends on the individual actually monitoring alerts and responding quickly. If someone receives a credit monitoring alert at midnight but doesn’t check email until morning, the fraudster may have already opened an account. Additionally, these services typically run for 12 to 24 months, but identity theft risks from exposed SSNs and health insurance information can persist for years. Affected individuals should also consider placing fraud alerts with the major credit bureaus and, if they have reason to believe their information is actively being misused, placing a credit freeze. These steps are free and provide stronger protection than monitoring services alone.
What Does the Centers Lab Breach Tell Us About Healthcare Data Security?
The Centers Lab breach illustrates a persistent vulnerability in healthcare infrastructure: diagnostic and laboratory companies, while handling sensitive patient data equivalent to what hospitals collect, often lack comparable security investment. These organizations are smaller and more specialized than major hospital systems, frequently lack dedicated security teams, and may operate under tighter budget constraints. WorldLeaks and similar groups specifically target organizations in this tier because they perceive a lower likelihood of sophisticated detection and a higher likelihood of payment in response to extortion demands. The 542,000-person breach demonstrates that a single compromised organization can expose hundreds of thousands of individuals in healthcare networks.
The fact that the breach was not discovered until eleven days after it ended underscores the reality that detection capability is uneven across the healthcare sector. Large hospital systems typically have security monitoring that can identify suspicious data access within hours. Smaller diagnostic labs may lack the infrastructure to detect unauthorized access at all. Federal regulations require HIPAA-covered entities to implement administrative, physical, and technical safeguards, but the regulations do not specify technologies or enforcement mechanisms with sufficient precision to prevent breaches like this one. The breach was large enough to reach the OCR notification threshold, placing Centers Lab on the public breach portal, but regulatory penalties—while potentially significant—do not compensate affected individuals for years of identity theft risk.
- —
Frequently Asked Questions
How do I know if I was affected by the Centers Lab breach?
Centers Lab has been notifying affected individuals by mail and email. You can check if your personal information was involved by looking for official notification from the company or by contacting Centers Lab directly if you received medical testing services through them between August 2025 and the present.
What should I do if my information was exposed?
Enroll in the complementary credit monitoring and identity theft protection offered by Centers Lab. Place a fraud alert or credit freeze with the major credit bureaus (Equifax, Experian, TransUnion). Monitor your credit reports regularly for unauthorized accounts or inquiries. Consider registering for the class action litigation when formal suits are filed.
Can I sue Centers Lab directly?
You have a potential claim, but the practical route is likely through the class action investigations announced by Edelson Lechtzin LLP and Schubert Jonckheer & Kolbe LLP. Both firms are investigating and may file formal class actions. Once filed, you may be able to opt in or participate in the settlement if the case succeeds.
How long could identity theft from this breach affect me?
Identity theft risks from exposed SSNs and health insurance information can persist for years, potentially indefinitely. The 12 to 24 months of monitoring provided by Centers Lab is a starting point, but maintaining vigilance with credit reports and financial accounts for several years is prudent.
Could my medical information be used against me by insurance companies?
That is a concern if exposed medical records reveal pre-existing conditions or treatments. However, the Affordable Care Act prohibits health insurers from denying coverage or charging more based on pre-existing conditions. If you switch insurers, ensure you disclose your actual medical history rather than relying on Centers Lab’s records.
Why wasn’t the breach discovered faster?
The attacker likely accessed the systems during off-hours and configured access to mimic normal administrative activity. Smaller healthcare organizations like Centers Lab may not have real-time security monitoring comparable to large hospital systems, making rapid detection difficult. This is a widespread vulnerability in the healthcare sector.
