HackingCapture Stored DataData ExfiltratedCustomer Data InvolvedIDENTITY_BASICHEALTH_BASICPIILowContained
Cencora
bd_4491a5aa23be3dd6 · schema v1 · pii pii-v1
Full breach record for Cencora →Cencora, Inc. notified Vermont consumers of a data security incident discovered on Feb 21, 2024, where data was exfiltrated from its systems. Affected personal information included names, addresses, DOBs, health diagnoses, and medications. Cencora engaged forensic experts and law enforcement, and is offering 24 months of credit monitoring via Experian.
Vermont clock✗ VT AG >45 bday14 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 21 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_e220668d43425551Vermont State AGfiled 2024-05-28Candidate
- bd_329f2aecc0d61184Vermont State AGfiled 2024-05-30(2d gap)Candidate
- bd_7eb5605247087ac3Vermont State AGfiled 2024-05-30(2d gap)Candidate
- bd_81ff8bb85d5b8e34Vermont State AGfiled 2024-05-31(3d gap)Candidate
Show 6 more filings ↓Show fewer ↑up to 64d gap
- bd_e062f954f4eceb7eVermont State AGfiled 2024-05-31(3d gap)Candidate
- bd_4fcc2ea1dc5c13f8Vermont State AGfiled 2024-06-03(6d gap)Candidate
- bd_e697a214cc3e6bd9Vermont State AGfiled 2024-06-07(10d gap)Candidate
- bd_3653594e7e26a7f0Vermont State AGfiled 2024-07-08(41d gap)Candidate
- bd_fd1a03e82376d629Vermont State AGfiled 2024-07-30(63d gap)Candidate
- bd_ac523b4cfa08ed6aSEC 8-Kfiled 2024-07-31(64d gap)Candidate
Showing first 10 of 20 linked disclosures.
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-05-28-smith-nephew-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 28, 2024
- Raw hash
- 3826cc3e16fc720b20549be91d9a60ba4c3ecd47b999338bc7640c37abcb7c2f
Reporting entity
- Name
- Cencoranorm: cencora
- Domain
- cencora.com
Victim entity
- Name
- Cencoranorm: cencora
- Domain
- cencora.com
Incident
- Discovered
- Feb 21, 2024
- Materiality determined
- —
- Notification sent
- May 28, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 ChannelT1119 Automated Collection
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 14 weeks(97 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.