HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
Cencora
bd_c414782630f5c48c · schema v1 · pii pii-v1
Full breach record for Cencora →Cencora, Inc. notified Delaware AG on May 28, 2024, of a data security incident discovered on February 21, 2024. Unauthorized actors exfiltrated data from Cencora's information systems, affecting personal information (name, address, DOB), health diagnoses/medications, and financial account numbers. Cencora engaged law enforcement and cybersecurity experts, contained the breach, and offered 24 months of credit monitoring via Experian. No evidence of fraud was found at the time of notification.
This filing is one of 40 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_225434215343f740Vermont State AGfiled 2024-05-31(3d gap)Verified
- bd_2f627285f2f041f2California State AGfiled 2024-05-31(3d gap)Verified
- bd_b9a4dc86f510194fCalifornia State AGfiled 2024-06-03(6d gap)Verified
- bd_0d319f20684cf4c8California State AGfiled 2024-06-05(8d gap)Candidate
Show 6 more filings ↓Show fewer ↑up to 41d gap
- bd_963c68d0dad2686dVermont State AGfiled 2024-06-05(8d gap)Verified
- bd_9c16b27470822eb3Vermont State AGfiled 2024-06-05(8d gap)Candidate
- bd_9af1f290af4dcb0cCalifornia State AGfiled 2024-06-10(13d gap)Candidate
- bd_13b5600dd58fb13cCalifornia State AGfiled 2024-06-20(23d gap)Verified
- bd_1c074a8994b49b5fVermont State AGfiled 2024-06-20(23d gap)Verified
- bd_3fed8c71645b986bCalifornia State AGfiled 2024-07-08(41d gap)Candidate
Showing first 10 of 39 linked disclosures.
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2024/05/Johnson-Johnson-Patient-Assistance-Foundation-L01_Redacted-5-28-24.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 28, 2024
- Raw hash
- 95085cf61caeca659a98084d7f8edde6109b71090a8bf300eb5c01bf0bdb7d36
Reporting entity
- Name
- Cencoranorm: cencora
- Domain
- cencora.com
Victim entity
- Name
- Cencoranorm: cencora
- Domain
- cencora.com
Incident
- Discovered
- Feb 21, 2024
- Materiality determined
- —
- Notification sent
- May 28, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- assistance of law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 14 weeks(97 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.