HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Cencora
bd_1c074a8994b49b5f · schema v1 · pii pii-v1
Full breach record for Cencora →Cencora, Inc. notified Vermont AG that on Feb 21, 2024, data from its systems was exfiltrated, potentially containing personal information. Cencora engaged law enforcement and cybersecurity experts. Affected data includes names, SSNs, and financial account numbers. Cencora offers 24 months of credit monitoring via Experian. No evidence of fraud found.
Vermont clock✗ VT AG >45 bday17 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 40 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_13b5600dd58fb13cCalifornia State AGfiled 2024-06-20Verified
- bd_9af1f290af4dcb0cCalifornia State AGfiled 2024-06-10(10d gap)Candidate
- bd_0d319f20684cf4c8California State AGfiled 2024-06-05(15d gap)Candidate
- bd_963c68d0dad2686dVermont State AGfiled 2024-06-05(15d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 20d gap
- bd_9c16b27470822eb3Vermont State AGfiled 2024-06-05(15d gap)Candidate
- bd_b9a4dc86f510194fCalifornia State AGfiled 2024-06-03(17d gap)Verified
- bd_3fed8c71645b986bCalifornia State AGfiled 2024-07-08(18d gap)Candidate
- bd_225434215343f740Vermont State AGfiled 2024-05-31(20d gap)Verified
- bd_2f627285f2f041f2California State AGfiled 2024-05-31(20d gap)Verified
- bd_3e2ae0a57615759cCalifornia State AGfiled 2024-05-31(20d gap)Candidate
Showing first 10 of 39 linked disclosures.
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-06-20-acrotech-biopharma-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 20, 2024
- Raw hash
- 7405e746646e5663e3f87acf6b37882ff79ee356511ed35a9edaeb192b2fb27f
Reporting entity
- Name
- Cencoranorm: cencora
- Domain
- cencora.com
Victim entity
- Name
- Cencoranorm: cencora
- Domain
- cencora.com
Incident
- Discovered
- Feb 21, 2024
- Materiality determined
- —
- Notification sent
- Jun 20, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 ChannelT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- assistance of law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 17 weeks(120 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.