MalwareRansomwareBlackCatData ExfiltratedData EncryptedCustomer Data InvolvedEmployee Data InvolvedRansom DemandedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCriticalContained
HENRY SCHEIN, INC.
bd_e6ff33d71b709e98 · schema v1 · pii pii-v1
Full breach record for HENRY SCHEIN, INC. →Henry Schein, Inc. filed a security breach notice with the South Carolina Department of Consumer Affairs on January 14, 2025, regarding a ransomware attack by the BlackCat group that occurred on October 14, 2023. The incident compromised the personal information of approximately 166,000 individuals, including employees and customers, affecting names, Social Security numbers, and financial account data. The company engaged forensic investigators, notified law enforcement, and sent notification letters to affected parties.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_4b1727b048fdc855California State AGfiled 2023-12-06(8d gap)Verified
- bd_817f39c882aae4e0Maine State AGfiled 2023-12-06(8d gap)Verified
- bd_6c3ca5d013cd7be2Montana State AGfiled 2023-11-17(11d gap)Verified
- bd_cc87b9a5cdf301c1Vermont State AGfiled 2023-11-17(11d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 59d gap
- bd_838851b9407ab003SEC 8-Kfiled 2023-11-16(12d gap)Verified
- bd_ad54e6e188668b37New Hampshire State AGfiled 2023-11-16(12d gap)Verified
- bd_72816974130743b6Washington State AGfiled 2024-01-26(59d gap)Verified
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Security%20Breach%20Notices/HenryScheinInc.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 28, 2023
- Raw hash
- 637b52f72ea1717b66f726464dbe44335f878be891aa30d0a72938a8f0ea3e44
Reporting entity
- Name
- HENRY SCHEIN, INC.norm: henry schein
- Domain
- henryschein.com
Victim entity
- Name
- HENRY SCHEIN, INC.norm: henry schein
- Domain
- henryschein.com
Incident
- Discovered
- Oct 14, 2023
- Materiality determined
- —
- Notification sent
- Jan 14, 2025
- Affected individuals
- 166,000
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Ransomware· BlackCat
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1190 Exploit Public-Facing Application
- Threat actor
- BlackCatExternalFinancial
- Regulator citations
- Notified South Carolina Department of Consumer Affairs
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(45 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.