HackingCapture Stored DataData ExfiltratedTargetedIDENTITY_BASICHEALTH_BASICPIILowContained
Cencora
bd_329f2aecc0d61184 · schema v1 · pii pii-v1
Full breach record for Cencora →Cencora, Inc. (via Lash Group) notified Vermont consumers of a data security incident discovered on Feb 21, 2024, where data was exfiltrated from its information systems. Affected personal information included names, addresses, DOBs, health diagnoses, and medications. Cencora engaged law enforcement and cybersecurity experts, provided 5 years of credit monitoring, and reinforced security protocols. No evidence of fraud was found at the time of notice.
Vermont clock✗ VT AG >45 bday14 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 21 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_7eb5605247087ac3Vermont State AGfiled 2024-05-30Candidate
- bd_81ff8bb85d5b8e34Vermont State AGfiled 2024-05-31(1d gap)Candidate
- bd_e062f954f4eceb7eVermont State AGfiled 2024-05-31(1d gap)Candidate
- bd_4491a5aa23be3dd6Vermont State AGfiled 2024-05-28(2d gap)Candidate
Show 6 more filings ↓Show fewer ↑up to 62d gap
- bd_e220668d43425551Vermont State AGfiled 2024-05-28(2d gap)Candidate
- bd_4fcc2ea1dc5c13f8Vermont State AGfiled 2024-06-03(4d gap)Candidate
- bd_e697a214cc3e6bd9Vermont State AGfiled 2024-06-07(8d gap)Candidate
- bd_3653594e7e26a7f0Vermont State AGfiled 2024-07-08(39d gap)Candidate
- bd_fd1a03e82376d629Vermont State AGfiled 2024-07-30(61d gap)Candidate
- bd_ac523b4cfa08ed6aSEC 8-Kfiled 2024-07-31(62d gap)Candidate
Showing first 10 of 20 linked disclosures.
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-05-30-sanofi-us-services-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 30, 2024
- Raw hash
- 9bf9a23ac4ac8e6aa3820b23cd9fc3f845174963c2a42ee3918c7ff5b4a2ab9d
Reporting entity
- Name
- Cencoranorm: cencora
- Domain
- cencora.com
Victim entity
- Name
- Cencoranorm: cencora
- Domain
- cencora.com
Incident
- Discovered
- Feb 21, 2024
- Materiality determined
- —
- Notification sent
- May 30, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 ChannelT1119 Automated Collection
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 14 weeks(99 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.