HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTHighContained
Johnson and Johnson Health Care Systems, Inc.
bd_a41f825c6f6f07d1 · schema v1 · pii pii-v1
Full breach record for Johnson and Johnson Health Care Systems, Inc. →Johnson & Johnson Health Care Systems, Inc. (Janssen) notified IBM, its service provider, of unauthorized access to the Janssen CarePath database. IBM and a third-party database provider remediated the technical vulnerability and conducted an investigation. The incident, discovered on August 2, 2023, potentially exposed names and government identifiers (e.g., SSN) for approximately 10,000 Rhode Island residents. No financial account or SSN data was in the database. Affected individuals were offered one year of credit monitoring.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_26bd4196d7328107Delaware State AGfiled 2023-09-22Verified
- bd_33114d6ef501acf4Vermont State AGfiled 2023-09-15(7d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/10/Johnson-and-Johnson-Sample-Individual-Notice-Letter.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 22, 2023
- Raw hash
- 7289933736840eed8fb2baf9795e692ec01f059c293d590dc71fedf5aa1f3c62
Reporting entity
- Name
- INTERNATIONAL BUSINESS MACHINES CORPnorm: international business machines
- Domain
- ibm.com
Victim entity
- Name
- Johnson and Johnson Health Care Systems, Inc.norm: johnson and johnson health care
Incident
- Discovered
- Aug 2, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 10,000
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified state Attorneys General (Delaware, DC, Maryland, New York, North Carolina, Rhode Island, Iowa, Oregon, New Mexico)
- Third party
- via International Business Machines Corporation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(51 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.