DisclosureLens
HackingHealthcareTechnologyHealthcareStolen CredentialsData MishandlingSupply Chain (3P Vendor)Customer Data InvolvedEmployee Data InvolvedGovernment IDIdentity (basic)FinancialMediumContained

GlaxoSmithKline (GSK)

bd_a1ca24b9d09f6bec · schema v1 · pii pii-v1

Severity

Medium

Discovered

Mar 14, 2016

Filed

Mar 25, 2016

To disclose

11 days

Affected · nationwide

5664 in this filing

Confidence

66%
Full breach record for GlaxoSmithKline (GSK)

GlaxoSmithKline (GSK) notified employees of a data breach involving a third-party vendor storing W-2 and payroll data. Unauthorized access occurred Feb 7–Mar 13, 2016. Affected data included SSNs, names, addresses, income info, and DOBs for approx. 566 US employees. GSK engaged federal authorities, provided 12 months of identity protection via InfoArmor, and the vendor closed the access point.

Incident timeline

undetected · 36 days
discovery → filing · 11 days

Feb 7, 2016

Begins

Mar 14, 2016

Discovered

Mar 25, 2016

Filed

vs. sector median

11 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed566 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.