HackingHealthcareManufacturingHealthcareCapture Stored DataData ExfiltratedSupply Chain (3P Vendor)Customer Data InvolvedDelayed DiscoveryIDENTITY_BASICHEALTH_BASICPHILowContained
PFIZER INC.
bd_43fd3ad486c2c2b5 · schema v1 · pii pii-v1
Full breach record for PFIZER INC. →Cencora, Inc. and its Lash Group affiliate, a third-party partner supporting Pfizer Inc.'s patient support programs, experienced a data exfiltration incident detected on February 21, 2024. Personal information including names, addresses, dates of birth, health diagnoses, and medications/prescriptions was potentially affected. On April 10, 2024, Cencora confirmed affected individuals. Cencora launched an investigation with law enforcement and cybersecurity experts and is offering 24 months of Experian credit monitoring.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_e803596bb5c033cdVermont State AGfiled 2024-06-07Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-586568
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 7, 2024
- Raw hash
- e764797edad8cbc67f75b6119bb54316ba2b18b64d739d2f31f0b9c96c55cb0c
Reporting entity
- Name
- Cencoranorm: cencora
- Domain
- cencora.com
Victim entity
- Name
- PFIZER INC.norm: pfizer
- Domain
- pfizer.com
- Industry
- Pharmaceutical
- Industry
- HealthcarellmManufacturingllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 ChannelT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Notified California Office of the Attorney General
- Third party
- via Cencora, Inc. / Lash Group
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.