Ag.Ny Labcorp Data Breach Settlement Secures $2.3 Million for Affected Consumers
Article Content
- •Labcorp's data breach exposed information of over 27.5 million people.
- •A settlement of $2.3 million requires Labcorp to enhance data security practices.
- •A separate class action lawsuit resulted in a $6.1 million settlement for a later breach.
A data breach involving Labcorp's debt collector, AMCA, exposed personal information of over 27.5 million individuals, including 10.2 million Labcorp patients. The breach occurred between August 1, 2018, and March 30, 2019, when a hacker accessed AMCA's internal systems, compromising sensitive data such as Social Security numbers and payment card information. New York Attorney General Letitia James announced a settlement that mandates Labcorp to pay $2.3 million and implement significant reforms to enhance data security practices. Additionally, a separate class action lawsuit concerning a later breach discovered in October 2024 has led to a $6.1 million settlement for impacted individuals, specifically those who received lab tests through Planned Parenthood. This breach affected approximately 1.6 million people and involved the exposure of personally identifiable information and protected health information. Labcorp is now required to improve its information security program and vendor management practices to prevent future breaches.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Labcorp in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…
Massive Network of AI Proxy Servers Used for Malicious Activities Uncovered Security researchers from Team Cymru have identified over 10,000 proxy servers in China facilitating malicious AI activities. These servers, termed 'transfer stations,' are primarily used to bypass geographic restrictions and conduct model distillation attacks against frontier AI models. The infrastructure allows…