BRISTOL-MYERS SQUIBB COMPANY
bd_c7f73efea8f4322f · schema v1 · pii pii-v1
Full breach record for BRISTOL-MYERS SQUIBB COMPANY →7 incidents on fileBristol Myers Squibb disclosed a cybersecurity incident involving the MOVEit SFTP tool, a third-party vendor product. Unauthorized access occurred as early as May 27, 2023, discovered on May 31, 2023. The breach affected up to 2,231 Washington residents, exposing names, DOBs, contact details, employment status, and SSNs for 45 individuals. Notices were sent starting June 29, 2023, offering 24 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
May 27, 2023
Begins
May 31, 2023
Discovered
Jun 30, 2023
Filed
vs. sector median
8 wks faster
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Montana State AGbd_27d9a6315eb19d822023-06-29 · +1dVerified
- New Hampshire State AGbd_333dbf505a7fad0d2023-07-03 · +3dVerified
- Massachusetts State AGbd_fd0e0b317e579e4b2023-07-05 · +5dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Pattern: first filing Jun 29 (MT), last Jul 5 (MA) — a 6-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.