PharMerica Corporation
bd_8eba9730c399eacb · schema v1 · pii pii-v1
Full breach record for PharMerica Corporation →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Moneymessage on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
Headquartered in Louisville, Kentucky, PharMerica is one of the largest and fastest-growing institutional pharmacy companies in the United States. Our premier pharmacy services, with more than 180 long-term care pharmacies in almost every state, have a national scope but a local approach.Revenue: $3BBrightSpring Health Services is the leading provider of complementary home- and community-based health services for complex populations in need of specialized and/or chronic care. We focus on providing quality outcomes, through best-in-class service and technology capabilities.Revenue: $5.4B
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Apr 8, 2023
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- Oregon State AGbd_226e2c119c0136712023-05-12 · +34dVerified
- HHS OCRbd_64333830485a7e132023-05-12 · +34dVerified
- Massachusetts State AGbd_43671b7376eb2cca2023-06-08 · +61dVerified
- Delaware State AGbd_a43e9112bb1c5c482023-06-08 · +61dVerified
Show 6 more filings ↓Show fewer ↑up to 97d gap
- New Hampshire State AGbd_c5ae4f6cd021f0912023-06-08 · +61dVerified
- Montana State AGbd_daca18683c969f622023-06-08 · +61dVerified
- South Carolina State AGbd_c9be2bf2de7485452023-06-09 · +62dVerified
- Maine State AGbd_e9b259e070676bf32023-06-09 · +62dVerified
- California State AGbd_c2b1450efa997e5b2023-06-19 · +72dVerified
- Illinois State AGbd_8ef22d9b75b7148c2023-01-01 · +97dCandidate
Filing propagation · 11 filings · 10 states
View merged incident ↗Pattern: first filing Jan 1 (IL), last Jun 19 (CA) — a 169-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
moneymessage
According to ransomware.live, Money Message emerged in March 2023 targeting Windows and Linux systems across banking, transportation, and professional services sectors, demanding ransoms in the millions and publishing stolen data on their blog if unpaid, with most known victims based in the US.