HackingHealthcareProfessional ServicesHealthcareCapture Stored DataData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)Delayed DiscoveryPIIPHIIDENTITY_BASICHEALTH_BASICLowContained
Abbott in Malaysia
bd_8824d369d7e960a0 · schema v1 · pii pii-v1
Full breach record for Abbott in Malaysia →Cencora, Inc. and its Lash Group affiliate disclosed that on February 21, 2024, data was exfiltrated from Cencora's information systems, potentially containing personal and health information of individuals enrolled in pharmaceutical customer support programs. Affected data included names, addresses, dates of birth, health diagnoses, and medications/prescriptions. The notice was sent by Abbott as a pharmaceutical partner of Lash Group. Cencora engaged law enforcement and cybersecurity experts and offered 24-month Experian credit monitoring to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-586078
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 29, 2024
- Raw hash
- 9a9289822353078f7b0e0436b6891d9df08349f7ec71f27db725ca7a89a526da
Reporting entity
- Name
- Cencoranorm: cencora
- Domain
- cencora.com
Victim entity
- Name
- Abbott in Malaysianorm: abbott in malaysia
- Domain
- my.abbott
- Industry
- HealthcarellmProfessional Servicesllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 ChannelT1119 Automated Collection
- Threat actor
- External
- Third party
- via Cencora, Inc. / Lash Group
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.