A data-extortion crew operating as LeakNet published a preview on July 27, 2026 claiming it holds an 11TB archive stolen from NYC Health + Hospitals (NYC H+H), the largest public health system in the United States, with data linked to more than 12 million people. That figure is the attacker's own and has not been confirmed by the health system, by regulators, or by any independent forensic review. The numbers NYC H+H has actually filed are far smaller: a breach report to HHS on March 24, 2026 covering roughly 1.8 million patients and employees, and a separate June disclosure covering 58,778 patients through business associate Solventum. Reports on the affected population therefore range from 1.8 million (NYC H+H's own HHS filing, reflected on the OCR breach portal per Paubox) to LeakNet's unverified claim of 12 million-plus (Hackread). The gap between those two numbers is the central open question in this incident.
What Happened
The confirmed intrusion behind the 1.8 million-record disclosure ran from approximately November 25, 2025 through February 11, 2026. NYC H+H detected suspicious activity on February 2, 2026, meaning the actor sat undetected inside parts of the environment for roughly 11 weeks, and remained present for several days after detection. The health system reported the breach to HHS on March 24, 2026.
LeakNet's claim is a later and separate escalation. On July 27, 2026 the group posted a preview package containing database screenshots, medical spreadsheets, internal messages, and what it described as a full directory listing for the archive, threatening a further release. Hackread, which reviewed the material, reported that several screenshots contain visible patient names, addresses, phone numbers, Social Security numbers, dates of birth, and clinical information, with other images appearing to show mental health diagnoses, HIV records, cancer-related appointments, and fingerprint documents carrying NYC H+H branding.
Whether LeakNet's archive is the same intrusion, a repackaging of previously leaked material, or a distinct event has not been established. No source confirms a link. Treat the two as unconnected until the health system or a forensic report says otherwise.
There is also a third, smaller 2026 incident on record. Per DistilINFO, NYC H+H disclosed in a June 11 notice that business associate Solventum Health Information Systems suffered unauthorized access on or around March 29, 2026 affecting 58,778 patients, exposing names, addresses, dates of birth, medical record numbers, medical history and diagnoses. The threat actor posted that data to the dark web on April 19, two days before Solventum notified NYC H+H on April 21.
What Was Taken
The data types confirmed through the Senate HELP Committee's account of the 1.8 million-record breach are unusually broad: names, Social Security numbers, medical records, health insurance information, billing and claims data, precise geolocation data, and biometric information including fingerprints and palm prints. DirSec additionally reports government IDs among the exposed categories.
Biometrics are what set this apart. Passwords rotate, cards reissue, and SSN exposure can be partly blunted with fraud alerts and credit freezes. A fingerprint or palm print has no equivalent remedy. Once a template is out, it is out for the life of the patient, usable for identity fraud and for spoofing biometric authentication systems indefinitely. DirSec and Everykey both frame this correctly: for biometric data there is no post-breach fix, so the entire defensive budget has to be spent before the incident.
On volume, LeakNet's 11TB and 12 million-person claim should be read skeptically. As Hackread notes, screenshots cannot establish provenance for every file, and database row counts are not person counts. Rows routinely represent appointments, encounters, diagnoses, or transactions, so a 12 million-row table may map to a far smaller population of individuals. The 1.8 million figure is the one backed by a regulatory filing.
Why It Matters
NYC H+H is the fifth-largest healthcare breach reported to HHS OCR in the first half of 2026, behind TriZetto Provider Solutions (3,433,965), QualDerm Partners (3,117,874), Nacogdoches Memorial Hospital (2,507,073), and Navia Benefit Solutions (2,151,330). Paubox reports 189 large healthcare breaches affecting more than 19 million individuals through June 2026, with 173 of those attributed to hacking and IT incidents. Business associates and covered entities appear in the top ten in roughly equal measure.
The political exposure is already real. Senate HELP Committee Chairman Bill Cassidy sent a letter on June 4, 2026 to NYC H+H CEO Mitchell Katz and to New York City's mayor, Zohran Mamdani, demanding a response by June 18 on pre-breach security controls, the exact awareness timeline, which federal agencies were notified and when, and what remediation followed. Cassidy specifically pressed on the vendor access question and on reporting commitments beyond HIPAA minimums. Accounts of Mamdani's title differ across coverage: Paubox identifies him as mayor, while The Financial Wire refers to him as an assemblymember.
There is a regulatory tail here too. The Financial Wire notes that several states impose shorter notification windows and stricter handling rules when biometric identifiers are involved, citing Illinois BIPA as the sharpest example. A health system holding fingerprint and palm-print data at this scale is operating on a tighter compliance clock than one holding demographics alone.
The Attack Technique
No zero-day, no dramatic perimeter breach. The investigation indicates initial access came through a third-party vendor with weaker controls than the hospital system's own network, followed by roughly 11 weeks of undetected presence. That dwell time is the signature failure: VistaInfoSec attributes it to insufficient continuous log review, and it is the part of this incident most directly reproducible at other organizations.
The Solventum incident points at a likely delivery method for that class of vendor compromise. Solventum's remediation, per DistilINFO, included resetting compromised employee accounts, rotating passwords, tightening permissions on sensitive data, and expanding employee training specifically on vishing and other social engineering. Remediation that shape strongly implies a social engineering entry point rather than an exploited vulnerability, though Solventum has not stated that outright.
The pattern across all three 2026 events is consistent: the attacker does not attack the hardened target, they attack whoever the hardened target trusts.
What Organizations Should Do
- Inventory vendor access as an attack surface, not a contract. A signed HIPAA business associate agreement proves nothing about enforcement. Map every third party with network or data access, what they can reach, and under which identities, then reduce that reach to the minimum the service actually needs.
- Instrument for dwell time, not just for intrusion. Eleven weeks undetected is a detection engineering failure. Prioritize continuous log review and alerting on vendor and service accounts: off-hours authentication, unusual data volume egress, and access to record sets outside normal scope.
- Treat biometric stores as tier-zero assets. Fingerprint and palm-print templates cannot be reissued, so they warrant separate encryption keys, separate access control, dedicated alerting, and a hard justification for retention at all. If the business case for storing them is weak, delete them.
- Contract for notification speed. In the Solventum case the data hit the dark web before the covered entity was told. Write concrete notification deadlines, forensic cooperation obligations, and evidence-preservation requirements into vendor agreements, and test them.
- Rehearse the extortion-claim scenario. Have a pre-agreed process for validating or refuting attacker-published sample data quickly, and a communications posture that distinguishes claimed figures from filed figures. Silence lets the attacker's number become the headline number.
- Segment so a vendor compromise stays small. Access through an integrator should not yield medical histories, claims data, geolocation, and biometrics from one foothold. Network and data segmentation is what converts a vendor breach into a contained one.
Sources: LeakNet Claims 11TB of Data Stolen in NYC Health + Hospitals Breach | HIPAA Business Associate Agreement: NYC H+H Breach Lessons | NYC Health Hospitals Data Breach Affects Solventum Systems | When a Breach Includes Biometric Data: Rethinking What “Sensitive”... | Senate HELP Committee chair demands answers from NYC Health + Hospi... | The NYC Health + Hospitals Breach: Why Stolen Biometrics Can't Be R... | A breach at NYC Health + Hospitals exposed 1.8 million people, incl... | More than 19M affected by healthcare data breaches in 2026 so far