HackingDelayed DiscoveryIDENTITY_BASICPIILowContained
Johnson and Johnson Health Care Systems, Inc.
bd_33114d6ef501acf4 · schema v1 · pii pii-v1
Full breach record for Johnson and Johnson Health Care Systems, Inc. →IBM notified Johnson & Johnson Health Care Systems, Inc. (Janssen) of unauthorized access to the Janssen CarePath database. Access was discovered on August 2, 2023. The scope of access is undetermined. Data potentially exposed includes names and other PII; SSNs and financial data were not in the database. IBM remediated the vulnerability and offered one year of credit monitoring.
Vermont clock⏱ VT AG >14 bday6 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_26bd4196d7328107Delaware State AGfiled 2023-09-22(7d gap)Verified
- bd_a41f825c6f6f07d1Delaware State AGfiled 2023-09-22(7d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-09-15-johnson-johnson-health-care-systems-janssen-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 15, 2023
- Raw hash
- 650450fe6713dd1a26069e2dfe6145aae1f7ae13658839ceddc731478fb6cf53
Reporting entity
- Name
- INTERNATIONAL BUSINESS MACHINES CORPnorm: international business machines
- Domain
- ibm.com
Victim entity
- Name
- Johnson and Johnson Health Care Systems, Inc.norm: johnson and johnson health care
Incident
- Discovered
- Aug 2, 2023
- Materiality determined
- —
- Notification sent
- Sep 15, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Filed notice with Vermont Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(44 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.