HackingStolen CredentialsCustomer Data InvolvedData ExfiltratedPIIIDENTITY_BASICMediumContained
PharMerica Corporation
bd_c5ae4f6cd021f091 · schema v1 · pii pii-v1
Full breach record for PharMerica Corporation →PharMerica Corporation reported a data security incident to the New Hampshire Attorney General on June 8, 2023. An unknown third party accessed PharMerica's computer systems from March 12-13, 2023. The breach affected 17,451 New Hampshire residents, whose personal information was potentially obtained. PharMerica engaged cybersecurity experts, notified law enforcement, and offered complimentary credit monitoring and identity protection services to affected individuals.
Leak gap clock⏱ Leak >30d12 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed17,451 affectedView incident
A leak claim by moneymessage about this victim predates this filing by 60 days.View originating leak claim
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/pharmerica-brightspring-health-services-20230608.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 8, 2023
- Raw hash
- 7d753f5b1ce801c5ea984669eb6a3d84e88736c9ae0a97641639e9ea40aa53ec
Reporting entity
- Name
- PharMerica Corporationnorm: pharmerica
- Domain
- pharmerica.com
Victim entity
- Name
- PharMerica Corporationnorm: pharmerica
- Domain
- pharmerica.com
Incident
- Discovered
- Mar 13, 2023
- Materiality determined
- —
- Notification sent
- Jun 8, 2023
- Affected individuals
- 17,451
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified Attorney General of the State of New Hampshire
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 12 weeks(87 days from discovery to filing)
- Compliance flags
- Leak >30d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.