HackingCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumActive
HENRY SCHEIN, INC.
bd_ad54e6e188668b37 · schema v1 · pii pii-v1
Full breach record for HENRY SCHEIN, INC. →Henry Schein, Inc. notified New Hampshire AG that a cybersecurity incident occurred on or about October 14, 2023, affecting employee personal information. Approximately 104 NH residents were notified. The breach involved unauthorized access to manufacturing and distribution business systems. Response included taking systems offline, engaging forensic experts, notifying law enforcement, and offering credit monitoring.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_838851b9407ab003SEC 8-Kfiled 2023-11-16Verified
- bd_6c3ca5d013cd7be2Montana State AGfiled 2023-11-17(1d gap)Verified
- bd_cc87b9a5cdf301c1Vermont State AGfiled 2023-11-17(1d gap)Verified
- bd_e6ff33d71b709e98South Carolina State AGBlackCatfiled 2023-11-28(12d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 71d gap
- bd_4b1727b048fdc855California State AGfiled 2023-12-06(20d gap)Verified
- bd_817f39c882aae4e0Maine State AGfiled 2023-12-06(20d gap)Verified
- bd_72816974130743b6Washington State AGfiled 2024-01-26(71d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/henry-schein-20231116.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 16, 2023
- Raw hash
- f4d75c3725967324121e8f760ea7a528217c2aaab70114df5e1771290cb7df0b
Reporting entity
- Name
- HENRY SCHEIN, INC.norm: henry schein
- Domain
- henryschein.com
Victim entity
- Name
- HENRY SCHEIN, INC.norm: henry schein
- Domain
- henryschein.com
Incident
- Discovered
- Oct 14, 2023
- Materiality determined
- —
- Notification sent
- Nov 17, 2023
- Affected individuals
- 104
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- notified relevant law enforcement authorities
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(33 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.