A diagnostics lab breach from nearly a year ago is only now landing on the desks of security and compliance teams, a reminder that extortion-group timelines and regulatory disclosure timelines rarely move at the same speed.
Centers Lab NJ LLC, a New Jersey based clinical testing and laboratory services provider, has begun notifying roughly 540,000 individuals that their personal and health information was exposed in an intrusion that occurred between August 9 and 14, 2025, according to the company’s own notice of data privacy event. The company detected suspicious activity and isolated affected systems on August 25, 2025, but public notification did not go out until July 2026, nearly a year after the intrusion. The extortion group WorldLeaks listed the stolen data on its leak site in October 2025, claiming roughly 720 GB across 1.6 million files. The exposed data types include names, dates of birth, Social Security numbers, driver’s license or passport numbers, and health insurance and medical information.
Why it matters to the security leader: the twelve-month gap between detection and disclosure is the story as much as the breach itself. Healthcare and lab-services vendors sit downstream of hospitals, insurers, and physician practices that never touch the attacker directly but inherit the notification burden and reputational fallout once a vendor’s timeline finally surfaces. Any organization sending patient samples or billing data to a third-party lab should check exactly when, not just whether, its vendor contracts require breach notification.
The original insight: WorldLeaks runs the now-standard extortion playbook of listing victims for leverage well before any public breach notice exists, meaning the leak-site listing, not the eventual company letter, is often the earliest signal a downstream partner gets. Security teams with lab or healthcare-vendor relationships should monitor extortion leak-site listings directly, a pattern CyberTech has previously detailed in our coverage of ShinyHunters’ extortion-driven breach campaign against Oracle PeopleSoft customers.
Source: Centers Lab NJ LLC