Ransomware attack on New York Blood Center disrupts collections

Organization
New York Blood Center Enterprises
Exploit
Ransomware
Industry
Healthcare

New York Blood Center Enterprises, one of the largest independent blood collection and distribution organizations in the United States, detected suspicious activity on its IT systems on January 26, 2025. It confirmed several days later that the intrusion was a ransomware attack.

NYBC took systems offline while it worked to contain the incident, and staff fell back on manual processes. The Record reported that some blood drives were cancelled and donor appointments rescheduled, while the organization said collection continued at its donor centers with longer than usual processing times. The attack landed days after NYBC declared a blood emergency on January 22, citing a steep drop in donations.

The organization engaged third-party forensic specialists and notified law enforcement. No ransomware group publicly claimed the attack.

A later forensic review found the intruder had access to the network between January 20 and January 26, 2025 and copied a subset of files stored there. NYBC ultimately reported the breach as affecting 193,822 people, with exposed data including names alongside Social Security numbers, driver's license or other government identification numbers, and financial account information. Notification letters began going out on September 5, 2025, accompanied by a year of complimentary credit monitoring and identity theft protection.

Sources