Skip to main content
Back to overview
Medium

NYC Health + Hospitals Data Breach Disclosed

In an increasingly digital world, the threat of data breaches looms larger than ever.

Key points

  • Breach disclosed on March 24, 2026.
  • Unauthorized access occurred between November 25, 2025, and February 11, 2026.
  • Files containing PHI and PII were exfiltrated.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Phishing Social Engineering

Malware, Social, Hacking, Error activity

03

Potential impact

Data Exposure

Confidentiality, Availability

Published
Mar 24, 2026
Updated
Jul 22, 2026
Confidence
Medium
Evidence
3 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Malware, Social, Hacking, Error activity

Watch phishing, executive impersonation and account-takeover exposure.

  • Source type: supplier or third-party involvement

Business impact

Potential operational disruption
Impact area
Confidentiality, Availability
Likely asset
User or customer data, Server or cloud data store

Mentioned entities

NychealthandhospitalsData DisclosureNYC HealthFromOccurredElasticsearchCybernewsURLsMostTelegram

Quick context

Questions about this signal

What happened in this signal?

In an increasingly digital world, the threat of data breaches looms larger than ever. From multinational corporations to individual users, no one is immune. The headlines are filled with stories of compromised personal information, stolen financial data, and disrupted services, painting a stark picture of our vulnerability. This blog will delve into the recent surge of data breaches, examining the causes, consequences, and crucial steps we can take to protect ourselves. We’ll explore the latest trends, analyze the impact on businesses and consumers, and discuss the evolving landscape of cybersecurity . Data Breaches that Occurred in June 2026 1. 24B Stolen Credential Records Exposed In Open Infostealer Log Database A publicly exposed Elasticsearch database containing 24 billion stolen credential records was found online in June 2026. Cybernews researchers said the database held more than 8.3TB of data, including usernames, email addresses, plaintext passwords, login URLs, and source details tied to the records. Most records appeared to come from infostealer logs, Telegram cybercrime channels, previous breach collections, and datasets exported from live servers. Researchers said the data came from 36 sources, but they could not confirm how many records were duplicates or how many unique people were affected. The database is no longer publicly exposed, but the risk remains high for account takeover, credential stuffing, phishing, and attacks using reused passwords or stolen session data. The exposure has been covered by TechRepublic and Security Affairs as one of June 2026’s largest credential data exposures. Sources: Cybernews , Malwarebytes , TechRepublic , Security Affairs 2. Kodak Says Breach Was Contained As ShinyHunters Claims 2.2M Records Stolen Kodak confirmed a June 2026 data breach after ShinyHunters claimed it stole 2.2 million customer and corporate records. ShinyHunters listed Kodak on its dark web leak site on June 15 and set a June 18 deadline before threatening to leak the alleged data. Kodak said an unauthorized third party temporarily accessed a limited amount of company data. The company engaged external cybersecurity experts, worked with law enforcement, and said there was no current threat to its systems or operations. ShinyHunters claimed the stolen records included customer personal information and internal corporate data, but Kodak has not publicly verified the 2.2 million record figure or disclosed the full data scope. Sources: Cybernews, BleepingComputer, CPO Magazine, Malwarebytes, SecurityWeek 3. DentaQuest Breach Exposes 2.6M Accounts After ShinyHunters Leaks 234GB Of Data DentaQuest confirmed a June 2026 cybersecurity incident after ShinyHunters published an alleged 234GB data archive tied to the dental benefits administrator. Have I Been Pwned verified 2.6 million unique email addresses in the dataset, along with names, phone numbers, physical addresses, dates of birth, gender data, government-issued IDs, and health insurance information. The incident began as a May 2026 “pay or leak” extortion campaign, and the data was released after negotiations reportedly failed. Security Affairs reported that DentaQuest secured its environment, contained the attack, brought in third-party cybersecurity experts, notified law enforcement, and kept its systems operational with limited disruption. Sources: Have I Been Pwned , BleepingComputer, Security Affairs , TechRadar 4. Klue-Salesforce OAuth Token Breach Hits Multiple Companies Klue confirmed a June 2026 supply chain breach after attackers used compromised legacy credentials to access its integration environment and obtain OAuth tokens connected to customer platforms. The attack unfolded between 11 Jun and 12 Jun, 2026, and allowed unauthorized access to Salesforce CRM data across multiple customer environments. Salesforce disabled the Klue Battlecards integration on 17 Jun, while Klue revoked affected credentials, removed unauthorized code, disabled potentially impacted integrations, and opened a full investigation. Icarus claimed responsibility for the attack, and roughly two dozen Klue customers later confirmed impact. Reported victims included LastPass, Huntress, Recorded Future, Tanium, Jamf, Gong, Sprout Social, HackerOne, and others. The incident remains active after reports that another hacker group may have obtained samples of stolen Klue customer data and tried to extort affected companies directly 5. KDDI Email System Breach Exposes 14.22M Accounts KDDI disclosed a major email system breach on 23 Jun, 2026, after detecting unauthorized access on 17 Jun, 2026. The incident affected an email platform that KDDI provides to six Japanese internet service providers: STNet, KDDI Web Communications, JCOM, Chubu Telecommunications, Nifty, and Biglobe. Up to 14.22 million email addresses and passwords may have been exposed, including active, dormant, and canceled accounts.

When was this signal reported?

Shadow Tier lists Mar 24, 2026 as the signal date.

Which organization is connected to this signal?

Nychealthandhospitals is the organization connected to this public signal.

Explore Nychealthandhospitals
Which attack pattern is relevant?

This signal is connected to phishing and social-engineering intelligence based on its reported incident context.

Explore phishing and social-engineering intelligence
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence