FEDERALItem 1.05 · mandatoryHackingHealthcareHealthcareDrugs WholesaleData ExfiltratedCustomer Data InvolvedPIILowContained
Cencora
bd_e55605d0ad000845 · schema v1 · pii pii-v1
Full breach record for Cencora →On February 21, 2024, Cencora, Inc. learned that data had been exfiltrated from its information systems, some of which may contain personal information. The company took immediate containment steps and commenced an investigation with law enforcement, cybersecurity experts and external counsel. As of filing, the incident has not had a material impact on operations; financial-condition impact is not yet determined.
SEC clockMateriality determined Feb 21, 2024 → Filed Feb 27, 20246d ✓ SEC 4-day OK6 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/1140859/000110465924028288/tm247267d1_8k.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Feb 27, 2024
- Raw hash
- 49a620ea17158cd3d5d9fdce2d7d6c999bf072d4de99bb031eaaf14961d8b0fb
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Cencoranorm: cencora
- SEC CIK
- 0001140859
- Domain
- cencora.com
- Industry
- Pharmaceutical Distribution
Victim entity
- Name
- Cencoranorm: cencora
- SEC CIK
- 0001140859
- Domain
- cencora.com
- Industry
- Pharmaceutical Distribution
- Industry
- HealthcarellmNAICS 424210 · Drugs and Druggists' Sundries Merchant Wholesalers
Incident
- Discovered
- Feb 21, 2024
- Materiality determined
- Feb 21, 2024
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Engaged law enforcement
Compliance
- Time to disclose
- 6 days(6 days from discovery to filing)
- Compliance flags
- SEC 4-day OK · 6d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Feb 21, 2024→ Filed: Feb 27, 20246d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.