BRISTOL-MYERS SQUIBB COMPANY
bd_333dbf505a7fad0d · schema v1 · pii pii-v1
Full breach record for BRISTOL-MYERS SQUIBB COMPANY →7 incidents on fileBristol Myers Squibb notified New Hampshire AG of a MOVEit vulnerability exploitation. Unauthorized access occurred as early as May 27, 2023. Data of 5 NH residents, including SSNs and names, was exfiltrated. BMS engaged law enforcement, patched the vulnerability, and offered 24 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
May 27, 2023
Begins
May 31, 2023
Discovered
Jun 1, 2023
Scope determined
Jul 3, 2023
Filed
vs. sector median
7 wks faster
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Massachusetts State AGbd_fd0e0b317e579e4b2023-07-05 · +2dVerified
- Washington State AGbd_c7f73efea8f4322f2023-06-30 · +3dCandidate
- Montana State AGbd_27d9a6315eb19d822023-06-29 · +4dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Pattern: first filing Jun 29 (MT), last Jul 5 (MA) — a 6-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.