Cencora, Inc.
bd_136b572cd28de50e · schema v1 · pii pii-v1
Cencora, Inc. notified Montana residents of a data security incident involving its Lash Group affiliate. On February 21, 2024, Cencora learned that data from its information systems had been exfiltrated, potentially containing personal information including names, addresses, dates of birth, and health diagnoses/medications. Cencora engaged law enforcement and cybersecurity experts, contained the incident, and offered 24 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 21, 2024
Discovered
May 23, 2024
Filed
vs. sector median
+1 wks slower
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Washington State AGbd_0fc0913c8d09d3552024-05-23Candidate
- Indiana State AGbd_a067e764a5a210712024-05-23Verified
Filing propagation · 3 filings · 3 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.