HackingVulnerability ExploitCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICHEALTH_BASICLowContained
INTERNATIONAL BUSINESS MACHINES CORP
bd_b5d032662e10aadc · schema v1 · pii pii-v1
Full breach record for INTERNATIONAL BUSINESS MACHINES CORP →IBM disclosed unauthorized access to a database supporting the Janssen CarePath patient support platform. IBM identified the unauthorized access on August 2, 2023, after Janssen notified IBM of a technical method allowing access. IBM remediated the issue and augmented security controls. Affected data may include names and health-related information, but not SSNs or financial account data. IBM offered one year of credit monitoring.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_5ff6b97317a260e1Montana State AGfiled 2023-09-22Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-574033
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 22, 2023
- Raw hash
- 67a4e72c40dc3b8c5abc2f8163866effa2ae8274d52361c232e211dc470d266a
Reporting entity
- Name
- INTERNATIONAL BUSINESS MACHINES CORPnorm: international business machines
- Domain
- ibm.com
Victim entity
- Name
- INTERNATIONAL BUSINESS MACHINES CORPnorm: international business machines
- Domain
- ibm.com
Incident
- Discovered
- Aug 2, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Third party
- via Janssen
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(51 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.