DisclosureLens
Social EngineeringManufacturingManufacturingPhishingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedPIIIdentity (basic)Financial accountLowContained

Lonza Bioscience

bd_d02c2d131272fad1 · schema v1 · pii pii-v1

Severity

Low

Discovered

Dec 29, 2017

Filed

Jan 24, 2018

To disclose

26 days

Affected · nationwide

122 in this filing

Confidence

65%
Full breach record for Lonza Bioscience2 incidents on file

Lonza notified the NH AG of a phishing attack in Nov/Dec 2017 that compromised 12 employee WorkDay accounts (2 in NH). Hackers accessed credentials and viewed personal info, rerouting direct deposits for some. Lonza discovered the breach on Dec 29, 2017, implemented WorkDay security controls, and offered 2 years of credit monitoring.

Incident timeline

undetected · 58 days
discovery → filing · 26 days

Nov 1, 2017

Begins

Dec 29, 2017

Discovered

Jan 24, 2018

Filed

vs. sector median

7 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed12 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.