DisclosureLens
HackingHealthcareHealthcareCapture Stored DataData ExfiltratedCustomer Data InvolvedPIIIdentity (basic)LowContained

REVANCE THERAPEUTICS, INC.

bd_e49d1ca886a02735 · schema v1 · pii pii-v1

Severity

Low

Discovered

Apr 9, 2023

Filed

Jul 10, 2023

To disclose

13 weeks

Affected

Not disclosed

Linked

6 filings

Confidence

66%
Full breach record for REVANCE THERAPEUTICS, INC.

Revance Therapeutics, Inc. disclosed that an unauthorized third party accessed and exfiltrated personal information from its systems between March 15, 2023, and April 10, 2023. The company discovered the incident on April 9, 2023. Affected data includes names and other personal information. Revance terminated the attacker's access, engaged cybersecurity specialists, notified law enforcement, and offered two years of identity monitoring through Kroll.

Incident timeline

undetected · 25 days
discovery → filing · 13 weeks / 92 days

Mar 15, 2023

Begins

Apr 9, 2023

Discovered

Jul 10, 2023

Filed

vs. sector median

+2 wks slower

This filing is one of 6 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (5) · sorted by filing gap

Show 1 more filing

Filing propagation · 6 filings · 5 states

View merged incident ↗
Montana State AGJul 10 · first
Indiana State AGJul 10 · first
Maine State AGJul 10 · first
Maine State AGJul 10 · first
Massachusetts State AGJul 10 · first
California State AGJul 10 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.