MisusePrivilege AbuseCustomer Data InvolvedEmployee Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTHighContained
PFIZER INC.
bd_b37a8a3ce133b0f3 · schema v1 · pii pii-v1
Full breach record for PFIZER INC. →Pfizer Inc notified approximately 34,000 individuals (colleagues, former employees, and healthcare professionals) of a data breach in New Hampshire. An internal employee wrongfully removed confidential data from a Pfizer computer system in late 2006. Pfizer discovered the breach on July 10, 2007. Exposed data included names, SSNs/TINs, addresses, phone numbers, credit card/bank account numbers, and government IDs. Pfizer notified law enforcement, state Attorneys General, and credit bureaus, and provided two years of free identity theft protection via IDS.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed34,000 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/pfizer-20070824.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 24, 2007
- Raw hash
- a3dc1874d41e356ff85c2f62046e9c574b1e2324c4022721d0ca390880637e19
Reporting entity
- Name
- PFIZER INC.norm: pfizer
- Domain
- pfizer.com
Victim entity
- Name
- PFIZER INC.norm: pfizer
- Domain
- pfizer.com
Incident
- Discovered
- Jul 10, 2007
- Materiality determined
- —
- Notification sent
- Aug 24, 2007
- Affected individuals
- 34,000
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Insider
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- Internal
- Regulator citations
- Notified the Attorney General’s office in your state of residence
- Initial access
- insider_action
Compliance
- Time to disclose
- 6 weeks(45 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.