HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICHEALTH_BASICLowContained
Express Scripts, Inc.
bd_ced8b9f8cc34a516 · schema v1 · pii pii-v1
Full breach record for Express Scripts, Inc. →Express Scripts, Inc. reported a cybersecurity incident involving unauthorized access to its mobile application. Between April 30 and May 3, 2022, a bad actor used stolen credentials (user ID and password obtained from another breach) to access member accounts. The actor may have viewed prescription history for the last 24 months, including names, medication details, and pharmacy information. No financial data or SSNs were compromised. Express Scripts locked affected accounts and required password resets, and offered free identity theft protection via Equifax.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_c05ac047f6d07013Montana State AGfiled 2022-06-01(2d gap)Verified
- bd_692ca0e73337b6e0Delaware State AGfiled 2022-05-30(4d gap)Candidate
- bd_8ae6086e173bb504Montana State AGfiled 2022-07-10(37d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-554045
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 3, 2022
- Raw hash
- 7723282ff52adfe85f6634a5d13582ecd9800f53a234ea2ab551086f2f12d476
Reporting entity
- Name
- Express Scripts, Inc.norm: express scripts
- Domain
- express-scripts.com
Victim entity
- Name
- Express Scripts, Inc.norm: express scripts
- Domain
- express-scripts.com
Incident
- Discovered
- May 1, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 5 weeks(33 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.