Cencora
ent_019dd172700ac5f4a59d1e10f5956651
Disclosures
25+
SEC 8-K · State AG · 4 jurisdictions
Incidents
3
filings grouped by incident
Max affected reported
—
no filed count in sample
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Cencora
- Normalized
- cencora— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- AI8GXW8LG5WK7E9UD086
- SEC EDGAR CIK
- 0001140859
- Domain
- cencora.com
Disclosure history (newest 25)newest first
- FEDERALSEC 8-Kas victim2024-07-31
Cencora, Inc. filed an 8-K/A amending its February 27, 2024 disclosure of a cybersecurity incident discovered on February 21, 2024, in which data was exfiltrated from its information systems. Subsequent investigation confirmed exfiltrated data included PII and PHI, most of which is maintained by a Company subsidiary providing patient support services. The Company has notified affected parties and regulators, believes the incident is contained, and reports no evidence of public disclosure of the data.
- 🍁Vermont State AGas victim2024-07-30
Cencora, Inc. notified Vermont AG of a data security incident discovered on Feb 21, 2024, involving exfiltrated personal information of individuals in its patient support programs. Affected data included names, addresses, DOBs, health diagnoses, and medications. Cencora engaged law enforcement and cybersecurity experts, contained the incident, and offered 24 months of credit monitoring via Experian.
- 🍁Vermont State AGas victim2024-07-08
Lash Group, a partner of Cencora, Inc., notified consumers of a data security incident where data from Cencora's information systems was exfiltrated on February 21, 2024. Affected personal information included names, addresses, dates of birth, health diagnoses, and medications. Cencora engaged law enforcement and cybersecurity experts, contained the incident, and offered 24 months of credit monitoring. No evidence of fraud was found at the time of notification.
- 🐻California State AGas victim2024-07-08
Cencora, Inc. notified California residents of a data breach discovered on February 21, 2024, where data was exfiltrated from its information systems. Affected data may include names, addresses, dates of birth, health diagnoses, and medications. Cencora engaged law enforcement and cybersecurity experts, contained the incident, and is offering 24 months of credit monitoring.
- 🐻California State AGas victim2024-06-20
Cencora, Inc. (via Lash Group) notified California residents that data was exfiltrated from its information systems on February 21, 2024. The incident potentially affected personal information, including names, addresses, and Social Security numbers, of individuals involved in patient support programs. Cencora engaged law enforcement and cybersecurity experts, contained the incident, and is offering 24 months of credit monitoring.
- 🍁Vermont State AGas victim2024-06-20
Cencora, Inc. notified Vermont AG that on Feb 21, 2024, data from its systems was exfiltrated, potentially containing personal information. Cencora engaged law enforcement and cybersecurity experts. Affected data includes names, SSNs, and financial account numbers. Cencora offers 24 months of credit monitoring via Experian. No evidence of fraud found.
- 🐻California State AGas victim2024-06-10
Cencora, Inc. notified California residents that data from its information systems was exfiltrated on February 21, 2024. The incident potentially affected personal information including name, address, date of birth, health diagnosis, and medications. Cencora engaged law enforcement and cybersecurity experts, contained the incident, and is offering 5 years of credit monitoring to affected individuals.
- 🐻California State AGas reporting2024-06-07
Cencora, Inc. and its Lash Group affiliate, a third-party partner supporting Pfizer Inc.'s patient support programs, experienced a data exfiltration incident detected on February 21, 2024. Personal information including names, addresses, dates of birth, health diagnoses, and medications/prescriptions was potentially affected. On April 10, 2024, Cencora confirmed affected individuals. Cencora launched an investigation with law enforcement and cybersecurity experts and is offering 24 months of Experian credit monitoring.
- 🍁Vermont State AGas victim2024-06-07
Cencora, Inc. experienced a data breach on February 21, 2024, resulting in the exfiltration of personal information including names, addresses, dates of birth, health diagnoses, and medications. The Lash Group, a partner of Cencora, notified affected consumers in Vermont and other jurisdictions on June 7, 2024. No evidence of fraud was found. Cencora engaged forensic experts and law enforcement, and offered 24 months of credit monitoring via Experian.
- 🍁Vermont State AGas reporting2024-06-07
Cencora, Inc., a third-party service provider for Pfizer Inc., notified consumers of a data security incident discovered on February 21, 2024. Personal information, including names, addresses, dates of birth, health diagnoses, and prescriptions, was exfiltrated. Cencora engaged law enforcement and cybersecurity experts, contained the incident, and provided 24 months of credit monitoring. No evidence of fraud was found at the time of notification.
- 🐻California State AGas victim2024-06-05
On February 21, 2024, Cencora, Inc. learned that data from its information systems had been exfiltrated. The breach involved personal information held by its Lash Group affiliate in connection with patient support programs, including names, addresses, dates of birth, health diagnoses, and medications/prescriptions. Cencora engaged law enforcement, cybersecurity experts, and outside counsel. Affected individuals were offered 24 months of Experian IdentityWorks credit monitoring.
- 🍁Vermont State AGas victim2024-06-05
Cencora, Inc. notified consumers of a data breach discovered on February 21, 2024, where data from its information systems was exfiltrated. The incident affected personal information including names, addresses, dates of birth, health diagnoses, and medications/prescriptions. Cencora engaged law enforcement and cybersecurity experts, contained the incident, and offered 24 months of credit monitoring via Experian IdentityWorks. No evidence of fraud was found at the time of notification.
- 🍁Vermont State AGas victim2024-06-05
Cencora, Inc. notified consumers of a data breach discovered on February 21, 2024, where unauthorized actors exfiltrated personal information including names, addresses, dates of birth, health diagnoses, and medications. Cencora engaged law enforcement and cybersecurity experts, contained the incident, and provided 24 months of credit monitoring via Experian IdentityWorks.
- 🍁Vermont State AGas victim2024-06-03
Cencora, Inc. notified consumers of a data breach discovered on February 21, 2024, where unauthorized actors exfiltrated personal information including names, addresses, dates of birth, health diagnoses, and medications. Cencora engaged law enforcement and cybersecurity experts, contained the incident, and provided 24 months of credit monitoring via Experian. No evidence of fraud was found at the time of notification.
- 🐻California State AGas victim2024-06-03
Cencora, Inc. and its Lash Group affiliate discovered on February 21, 2024 that data had been exfiltrated from its information systems. Affected data includes patient names, addresses, dates of birth, health diagnoses, and medications/prescriptions. Cencora engaged law enforcement, cybersecurity experts, and outside counsel, and is offering 24-month Experian IdentityWorks credit monitoring to affected individuals.
- 🍁Vermont State AGas victim2024-05-31
Cencora, Inc. notified Vermont consumers of a data security incident discovered on February 21, 2024, where data from its information systems was exfiltrated. The incident potentially affected personal information including names, addresses, dates of birth, health diagnoses, and medications. Cencora engaged cybersecurity experts and law enforcement, reinforced security protocols, and offered 24 months of credit monitoring via Experian IdentityWorks.
- 🐻California State AGas victim2024-05-31
Cencora, Inc. notified California residents of a data breach discovered on February 21, 2024, involving the exfiltration of personal information from its information systems. Affected data may include names, addresses, dates of birth, health diagnoses, and medications. Cencora engaged law enforcement and cybersecurity experts, contained the incident, and is offering 24 months of credit monitoring to affected individuals.
- 🐻California State AGas victim2024-05-31
Cencora, Inc. notified California residents that data from its information systems was exfiltrated on February 21, 2024. The incident potentially affected personal information including name, address, date of birth, health diagnosis, and medications. Cencora engaged law enforcement and cybersecurity experts, contained the incident, and is offering 24 months of credit monitoring to affected individuals.
- 🍁Vermont State AGas victim2024-05-31
Cencora, Inc. notified consumers of a data security incident discovered on February 21, 2024, where data from its information systems was exfiltrated. The incident potentially affected personal information including names, addresses, dates of birth, health diagnoses, and medications. Cencora engaged law enforcement and cybersecurity experts, contained the incident, and offered 24 months of credit monitoring.
- 🐻California State AGas victim2024-05-31
Cencora, Inc. notified California residents that data from its information systems was exfiltrated on February 21, 2024. The incident potentially affected personal information including name, address, date of birth, health diagnosis, and medications. Cencora engaged law enforcement and cybersecurity experts, contained the incident, and is offering 24 months of credit monitoring.
- 🐻California State AGas victim2024-05-31
Cencora, Inc. notified the California Attorney General of a data breach involving its Lash Group affiliate. On February 21, 2024, Cencora learned that data from its information systems had been exfiltrated. The incident potentially affected personal information including names, addresses, dates of birth, health diagnoses, and medications. Cencora engaged law enforcement and cybersecurity experts, took containment steps, and is offering 24 months of credit monitoring to affected individuals.
- 🍁Vermont State AGas victim2024-05-31
Cencora, Inc. experienced a data breach on February 21, 2024, resulting in the exfiltration of personal information including names, addresses, dates of birth, health diagnoses, and medications. Lash Group, a partner, notified affected consumers on May 31, 2024. Cencora engaged law enforcement and cybersecurity experts, and offered 24 months of credit monitoring.
- 🐻California State AGas victim2024-05-30
Cencora, Inc. notified California residents that data from its information systems was exfiltrated on February 21, 2024. The incident potentially affected personal information including name, address, date of birth, health diagnosis, and medications. Cencora engaged law enforcement and cybersecurity experts, contained the incident, and is offering 24 months of credit monitoring.
- 🍁Vermont State AGas victim2024-05-30
Cencora, Inc. (via Lash Group) notified Vermont consumers of a data security incident discovered on Feb 21, 2024, where data was exfiltrated from its information systems. Affected personal information included names, addresses, DOBs, health diagnoses, and medications. Cencora engaged law enforcement and cybersecurity experts, provided 5 years of credit monitoring, and reinforced security protocols. No evidence of fraud was found at the time of notice.
- 💎Delaware State AGas victim2024-05-30
Cencora, Inc. notified Delaware AG on May 30, 2024, of a data security incident discovered on February 21, 2024. Unauthorized actors exfiltrated personal information, including names, addresses, dates of birth, health diagnoses, and financial account numbers, affecting individuals in Cencora's patient support programs. Cencora engaged law enforcement and cybersecurity experts, contained the breach, and offered 24 months of credit monitoring via Experian.
Subsidiary disclosures (6)filed by group companies
◈ These filings were made by or about subsidiaries of Cencora — not by Cencora itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- 🐻California State AGvia AmerisourceBergen Specialty Group, LLC2024-10-08
AmerisourceBergen Specialty Group, LLC notified California residents of a data breach involving exfiltration of personal and health information. The incident occurred on February 21, 2024. Affected data includes names, addresses, dates of birth, medical treatment information, health insurance information, and medical record numbers. The company engaged forensic experts and law enforcement, contained the incident, and is offering 24 months of credit monitoring.
- 🍁Vermont State AGvia AmerisourceBergen Specialty Group, LLC2024-10-08
AmerisourceBergen Specialty Group, LLC notified consumers of a data security incident where data was exfiltrated from its information systems. The incident, confirmed on August 14, 2024, compromised personal information including names, addresses, dates of birth, health insurance information, and medical record numbers. ABSG engaged cybersecurity experts and law enforcement, took containment steps, and is offering 24 months of credit monitoring and identity restoration services through Experian IdentityWorks.
- 🦬Montana State AGvia AmerisourceBergen Specialty Group, LLC2024-05-31
AmerisourceBergen Specialty Group, LLC - The Lash Group reported a data breach to the Montana Attorney General. The breach was reported on 2024-05-31. The breach occurred on 4/3/2024. 8 Montana residents were affected.
- 🍁Vermont State AGvia AmerisourceBergen Specialty Group, LLC2024-05-31
AmerisourceBergen Specialty Group, LLC notified consumers of a data security incident where data was exfiltrated from its information systems. The incident, confirmed on April 3, 2024, potentially exposed personal information including names, health insurance/Medicare/Medicaid numbers, treatment/prescription info, and dates of birth. ABSG engaged law enforcement and cybersecurity experts, reinforced security protocols, and offered 24 months of credit monitoring via Experian IdentityWorks.
- PAHHS OCRvia AmerisourceBergen Specialty Group, LLC2024-05-31
AmerisourceBergen Specialty Group, LLC reported to HHS on 2024-05-31 a Hacking/IT Incident affecting 3102 individuals. Breached information located on Network Server.
- PAHHS OCRvia AmerisourceBergen Specialty Group, LLC2024-05-24
AmerisourceBergen Specialty Group, LLC reported to HHS on 2024-05-24 a Hacking/IT Incident affecting 252214 individuals. Breached information located on Network Server.