This is typical alarmist reporting, designed to do nothing more than sell copy. The real issue is the process failure that allowed somebody to use an expired ID card to fool a security guard.
Two minutes worth of Googling and I came across this: An audit of the Police Department's (NYPD) data center and computer security disclosed that there is adequate physical and computer system security in the data center and that computer operations, as well as contingency plans, have been tested in compliance with applicable Federal Information Processing Standards and City guidelines....
They might want to revisit those guidelines!
So, while this was a data breach of sorts, the important bit from my perspective is the fact that a malicious employee was able to social engineer his way into a restricted area. It was an easily preventable incident.