11TB
stolen data LeakNet claims from NYC Health + Hospitals, now circulating on the dark web after the July 27 publication
1.8M
patients confirmed affected and reported to HHS; LeakNet claims the full archive contains records for 12 million people
78 days
window attackers maintained inside NYC Health + Hospitals via a third-party vendor before detection on February 2, 2026
0
fingerprints stolen in this breach that can ever be revoked, changed, or reissued -- biometric exposure from this breach is permanent

SponsoredHorizon3.ai

Proactive Security for the AI Era

NodeZero continuously and autonomously pentests infrastructure, identity, cloud, and now web applications, chaining weaknesses across every domain the way real attackers do. Every finding ships with replayable proof showing exploitable business impact, not theoretical risk.

See NodeZero WebApp in action

LeakNet published a preview of 11 terabytes of stolen data from NYC Health + Hospitals on a dark web leak site on July 27, 2026, exposing fingerprints, Social Security numbers, HIV records, mental health diagnoses, and bank account credentials that cannot be revoked or replaced.

The NYC Health Hospitals data breach is a live dark web event. Screenshots from LeakNet's post show visible patient names, addresses, phone numbers, Social Security numbers, and dates of birth alongside internal service desk notices confirming the group's access to production systems. The data covers anyone who received care at or worked for NYC Health + Hospitals since 2020, based on the breach period spanning November 25, 2025, through February 11, 2026. The attacker gained entry through a security failure at an unnamed third-party vendor that served the health system.

LeakNet did not exfiltrate data in a single event. The group maintained persistent access for 78 days, systematically collecting records before announcing the breach. The archive LeakNet claims to hold totals 11TB, a volume that spans databases, medical spreadsheets, insurance records, and complete directory listings. LeakNet has threatened to publish the full archive in a subsequent release if its demands are not met.

This breach is active now. If you or your employees received care at any NYC Health + Hospitals facility after 2020, your biometric data, financial accounts, insurance identifiers, and full medical history may already be available on dark web markets that sell identity fraud packages for as little as $20 per record. The free identity monitoring window is open until February 28, 2027. Act today.

How Did LeakNet Breach NYC Health + Hospitals?

The NYC Health Hospitals data breach originated at a third-party vendor, not directly at the health system's own network perimeter. NYC Health + Hospitals confirmed in its official breach notice that an unnamed third-party vendor experienced a security failure that gave the attacker access to health system data. The specific vendor and access vector have not been disclosed publicly. This pattern, where attackers compromise a trusted supplier to reach a high-value target, is the dominant initial access technique in healthcare breaches throughout 2025 and 2026.

LeakNet's documented initial access method is ClickFix, a social engineering technique where attackers compromise legitimate websites and serve fake CAPTCHA verification pages. Visitors see a verification prompt that instructs them to copy a command from their clipboard and paste it into the Windows Run dialog. The command executes msiexec.exe to download and run a Deno-based in-memory loader. The Deno runtime executes Base64-encoded payloads directly from memory, leaving minimal forensic artifacts on disk and bypassing endpoint tools that rely on scanning files written to the filesystem.

Once inside the third-party vendor's environment, LeakNet used standard post-exploitation techniques: DLL side-loading to launch additional payloads, credential enumeration via cmd.exe to identify accessible accounts, lateral movement using PsExec, and data exfiltration staged through Amazon S3 buckets to blend with normal cloud traffic.

The 78-day dwell time, from November 25, 2025, through February 11, 2026, indicates that LeakNet operated without triggering detection controls throughout the breach period. NYC Health + Hospitals detected suspicious activity on February 2, 2026, nine days before the attacker's final recorded access. The breach was publicly disclosed on March 24, 2026. LeakNet published its dark web preview on July 27, 2026, more than five months after the breach ended, holding the data as leverage before escalating to public exposure.

What NYC Health Hospitals Data Is Now on the Dark Web?

The LeakNet preview published on July 27 confirmed that the stolen archive contains data across every high-value category for identity fraud and medical extortion.

Medical records form the core of the stolen data. LeakNet's preview screenshots show medical spreadsheets containing diagnoses, treatment plans, medications, and test results. Visible categories include mental health diagnoses, HIV records, and cancer-related appointments. Medical identity theft, where criminals use stolen records to bill insurers for services the victim never received, costs the healthcare system an estimated $7.7 billion annually in fraudulent claims.

Biometric data is the most permanent component of this breach. NYC Health + Hospitals confirmed that fingerprints and palm prints are included in the stolen records. Biometric identifiers cannot be changed or reissued. Every affected patient and employee carries this exposure for life. Stolen fingerprints can defeat biometric authentication systems in corporate environments, border crossings, law enforcement databases, and consumer devices.

The breach also covers financial and identity data: credit and debit card numbers, bank account details, Social Security numbers, driver's licenses, passport copies, and online account credentials. LeakNet's preview includes screenshots showing complete rows of patient-level records with names, addresses, phone numbers, dates of birth, and insurance membership numbers visible without redaction.

NYC Health + Hospitals confirmed that the breach affects anyone who worked for or received care at the system since 2020. The officially confirmed affected count reported to the Department of Health and Human Services stands at 1.8 million. LeakNet claims the full archive contains 12 million people. Independent verification of that figure has not been completed. The potential scale rivals past large healthcare breaches covered in our analysis of the ShinyHunters Abbott Labs attack.

Free daily briefing

Briefings like this, every morning before 9am.

Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.

Who Is LeakNet? The Digital Watchdog That Targets Healthcare

LeakNet is a ransomware and data extortion group that emerged in November 2024, presenting itself as a "digital watchdog" committed to internet freedom and transparency. DarkFeed, a dark web threat intelligence service, confirmed the group listed over 10 victims on its darknet site within its first months of operation.

The group's technical signature is its ClickFix-based initial access chain. LeakNet compromises legitimate websites to serve fake CAPTCHA pages that trick users into executing msiexec.exe commands through the Windows Run dialog. A Deno-based in-memory loader then executes the second-stage payload directly from RAM, bypassing endpoint detection tools that scan files written to disk. This approach removes LeakNet's reliance on purchasing initial access from brokers, reduces per-victim cost, and lets the group scale targeting.

LeakNet's targeting has expanded from corporate IT environments into critical infrastructure and now into healthcare. The Hacker News documented LeakNet's March 2026 ClickFix campaigns attacking organizations across multiple industry verticals, with the group explicitly broadening into industrial targets. The NYC Health + Hospitals breach marks a further escalation: a municipal health system serving 12 million New Yorkers across 11 acute care hospitals, six long-term care facilities, and more than 70 community health centers.

LeakNet's extortion model follows the double extortion pattern used by major ransomware operators: exfiltrate data first, hold it as leverage, then escalate to public dark web exposure if demands go unmet. The July 27 preview is the escalation phase. NYC Health + Hospitals had not publicly addressed LeakNet's dark web post as of July 30, 2026.

LeakNet presents itself as a transparency advocate while running a criminal extortion operation against hospitals serving millions of patients. The 'digital watchdog' framing is cover for targeted data theft and ransom extraction.

DarkFeed threat intelligence, 2026

Sigma Detection Rules for LeakNet ClickFix Attacks

No CVE-specific Sigma rule exists for this breach. LeakNet gained access through a third-party vendor using ClickFix social engineering rather than a direct vulnerability in NYC Health + Hospitals systems. The three rules below target ClickFix's known execution behavior at the Windows registry and process creation level. These rules apply to every Windows environment in your organization and across your vendor population, which is the current LeakNet target pool.

All three rules require Windows Sysmon Event ID 1 (process creation) and Event ID 13 (registry value set) as log sources. Ingest these events into your SIEM. Run in detection mode for 24 hours before activating blocks, to baseline normal Windows Run dialog usage in your environment. Alert on any hit involving msiexec.exe executing from a non-standard directory.

Subscribe to unlock Sigma Detection Rules

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Subscribe to unlock WAF Detection Rules

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Indicators of Compromise and Defensive Resources

Specific network IOCs for the NYC Health Hospitals data breach have not been publicly confirmed. The breach originated at an unnamed third-party vendor, and LeakNet's specific infrastructure used in this intrusion has not been publicly documented as of July 30, 2026.

LeakNet's dark web leak site published a preview of the stolen archive on July 27, 2026. The preview screenshots visible to researchers contain unredacted patient names, addresses, Social Security numbers, dates of birth, and medical information. LeakNet has stated it will publish the remaining material in a future release.

For your vendor population, the key behavioral indicators to monitor are LeakNet's ClickFix delivery patterns: msiexec.exe executing from non-standard directories, Windows Run dialog registry entries containing HTTPS URLs with CAPTCHA-adjacent keywords such as verification, robot, or human, and outbound connections from workstations using the Deno JavaScript runtime as a User-Agent string. These patterns are covered by the Sigma rules in the prior section.

Subscribe to unlock Indicators of Compromise

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

How to Check If Your Data Is on the Dark Web Right Now

Seven actions to take immediately if you or your employees received care at any NYC Health + Hospitals facility since 2020. These steps apply whether or not you have received an official breach notification letter.

Subscribe to unlock Remediation & Mitigation steps

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Why the NYC Health Hospitals Data Breach Matters for Your Organization

The NYC Health Hospitals data breach is not only a patient exposure event. It is a model for how ransomware groups are shifting from operational disruption to long-term identity destruction.

LeakNet's approach is deliberate. The group did not deploy ransomware and demand payment within 72 hours. It waited 78 days inside the network, collected data systematically, held the archive for five months, then published a preview to maximize extortion pressure. This extended timeline gives defenders no clean response window. By the time the dark web preview appeared on July 27, 2026, the data had already been organized, verified, and prepared for sale.

The third-party vendor entry point is now the most critical risk in healthcare security architecture. NYC Health + Hospitals runs 11 acute care hospitals, 6 long-term care facilities, and over 70 community health centers. Its vendor ecosystem is correspondingly large. A single compromised vendor with read access to patient records gives an attacker everything LeakNet published without touching the health system's own perimeter controls. Every healthcare organization that conducts periodic vendor security assessments but does not continuously monitor vendor-side data access patterns faces the same exposure.

For security teams: the priority actions are applying the Sigma detection rules in this post to your endpoint telemetry, reviewing your third-party vendor risk assessments for entities with access to patient data, and enabling dark web monitoring for your organization's email domains. The LeakNet preview contained screenshots of internal service desk communications and internal directory listings, indicating the vendor breach included access to administrative systems, not just patient-facing applications.

The biometric component sets this breach apart from all prior healthcare data incidents. Past large-scale breaches, including the ShinyHunters Abbott Labs attack, exposed financial and identity data that can be partially mitigated through credit monitoring and credential rotation. Fingerprints cannot be rotated. Every patient whose biometric data appears in the LeakNet archive carries permanent exposure, with no available mitigation beyond heightened authentication vigilance for the rest of their lives.

The bottom line

The NYC Health Hospitals data breach is live on the dark web now. LeakNet's July 27 preview contains unredacted patient records including fingerprints, Social Security numbers, and mental health diagnoses from 1.8 million confirmed victims. Three actions matter above all: enroll in the Kroll identity monitoring program at nychealth-hospitalsincident.kroll.com before February 28, 2027; freeze your credit at Equifax, Experian, and TransUnion today; and rotate every password that might match your health system portal login. Biometric data cannot be replaced -- fingerprints stolen in this breach will expose affected individuals for life. Security teams should apply the three Sigma rules in this post to catch LeakNet ClickFix activity across their own environment and third-party vendor population.

This analysis is generic. create a free account to score threats like this against your own stack.

Frequently asked questions

What is the NYC Health + Hospitals data breach?

The NYC Health + Hospitals data breach is a confirmed intrusion in which an attacker gained access through a third-party vendor from November 25, 2025, through February 11, 2026, and exfiltrated records covering patients and employees since 2020. NYC Health + Hospitals confirmed 1.8 million individuals were affected and reported the breach to HHS. The ransomware and extortion group LeakNet published a preview of the stolen archive on a dark web leak site on July 27, 2026, claiming to hold 11TB of data including medical records, biometric fingerprints, Social Security numbers, and financial account details.

How do I know if my medical data was stolen in this breach?

You are potentially affected if you worked for or received care at any NYC Health + Hospitals facility since 2020. The health system sent notification letters to confirmed victims. If you have not received a letter but believe you are at risk, call (844) 403-4518 or visit nychealth-hospitalsincident.kroll.com to confirm eligibility for the 24-month identity monitoring program. All potentially affected individuals are encouraged to enroll regardless of whether they received a notification letter.

What is LeakNet ransomware?

LeakNet is a ransomware and data extortion group that emerged in November 2024. The group uses ClickFix, a social engineering technique that compromises legitimate websites to serve fake CAPTCHA pages that trick users into executing malicious commands via the Windows Run dialog. LeakNet deploys a Deno-based in-memory loader that executes payloads from RAM to minimize forensic traces. The group practices double extortion: exfiltrating data first, holding it as leverage, then escalating to dark web publication if ransom demands go unmet.

Can stolen biometric fingerprint data be used for identity theft?

Yes. Stolen fingerprint data can defeat biometric authentication systems in corporate environments, government databases, border control systems, law enforcement databases, and consumer devices such as smartphones and laptops. Unlike passwords or Social Security numbers, fingerprints cannot be changed or reissued. Every individual whose fingerprint data appears in the LeakNet archive faces permanent exposure. The primary risk is unauthorized physical and digital access to systems that use fingerprint authentication as a verification method.

What should I do if my fingerprints were stolen in a healthcare breach?

Fingerprints cannot be changed, so mitigation focuses on reducing reliance on fingerprint authentication as a sole verification method. Enroll in identity monitoring through nychealth-hospitalsincident.kroll.com. Contact any employer or financial institution using your fingerprint for authentication and request they add a secondary verification factor such as a PIN or security question. File a police report if you observe unauthorized physical access attempts. Monitor government identity databases and credit reports for signs of fraudulent identity use.

How do hackers use stolen medical records?

Stolen medical records enable several fraud categories. Medical identity theft uses records to bill insurers for procedures the victim never received. Prescription fraud uses diagnosis records to obtain controlled substances. Targeted phishing uses medical details to construct convincing campaigns against the victim and their family members. Life insurance and disability fraud uses medical history to file fraudulent claims. Records are also sold on dark web markets in bundled packages combining medical history, Social Security numbers, and financial account details.

How long did hackers have access to NYC Health + Hospitals?

Attackers maintained access for 78 days, from November 25, 2025, through February 11, 2026, via a compromised third-party vendor. Suspicious activity was detected on February 2, 2026, nine days before the attacker's final recorded access. The breach was publicly disclosed on March 24, 2026. LeakNet held the stolen data for over five months before publishing a preview on the dark web on July 27, 2026.

Is my data on the dark web now from the NYC Health + Hospitals breach?

LeakNet published a preview of the stolen archive on July 27, 2026, with screenshots showing visible patient names, addresses, Social Security numbers, dates of birth, and medical information. If you received care at or worked for any NYC Health + Hospitals facility since 2020, some portion of your records may be in the data now circulating on dark web forums. Check haveibeenpwned.com for your email addresses, enroll in the Kroll monitoring program, and freeze your credit immediately to limit damage from future misuse of the exposed data.

Sources & references

  1. NYC Health + Hospitals: Official Notice of Data Breach
  2. HackRead: LeakNet Claims 11TB of Data Stolen in NYC Health + Hospitals Breach
  3. HIPAA Journal: Up to 1.8 Million Individuals Affected by NYC Health + Hospitals Data Breach
  4. The Hacker News: LeakNet Ransomware Uses ClickFix via Hacked Sites, Deploys Deno In-Memory Loader
  5. TechCrunch: NYC Health and Hospitals says hackers stole medical data and fingerprints during breach affecting at least 1.8 million people

Free resources

25
Free download

Critical CVE Reference Card 2025–2026

25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.

No spam. Unsubscribe anytime.

Free download

Ransomware Incident Response Playbook

Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.

No spam. Unsubscribe anytime.

Free newsletter

Get threat intel before your inbox does.

50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.

Unsubscribe anytime. We never sell your data.

Eric Bang
Author

Founder & Cybersecurity Evangelist, Decryption Digest

Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.

Giveaway: InfoSec World 2026 All Access Pass ($3,895 value)

Details →
Daily Briefing

Subscribe to enter the giveaway

Every subscriber is automatically entered. You also get daily threat intel every morning: zero-days, ransomware, and nation-state campaigns. Free. No spam.

Already subscribed? You're already entered.

Giveaway

Win a $3,895 InfoSec World 2026 pass.