PFIZER INC.
ent_019e44ea4ff529854e5cd93730dc498e
Disclosures
5
SEC 10-K Item 1C · State AG · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
34,000
as filed · State AG NH
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- PFIZER INC.
- Normalized
- pfizer— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 765LHXWGK1KXCLTFYQ30
- SEC EDGAR CIK
- 0000078003
- Domain
- pfizer.com
Disclosure history (5)newest first
- FEDERALSEC 10-K Item 1Cas victim2026-02-26
Pfizer Inc. (CIK 78003) filed its 2025 Form 10-K disclosing no known cybersecurity incidents that have materially affected or are reasonably likely to materially affect the Company's business, strategy, operations, or financial condition for the fiscal year ended December 31, 2025. The filing details robust cybersecurity governance, including BOD oversight via the Audit Committee, a dedicated CISO, and alignment with NIST standards.
- 🐻California State AGas victim2024-06-07
Cencora, Inc. and its Lash Group affiliate, a third-party partner supporting Pfizer Inc.'s patient support programs, experienced a data exfiltration incident detected on February 21, 2024. Personal information including names, addresses, dates of birth, health diagnoses, and medications/prescriptions was potentially affected. On April 10, 2024, Cencora confirmed affected individuals. Cencora launched an investigation with law enforcement and cybersecurity experts and is offering 24 months of Experian credit monitoring.
- 🍁Vermont State AGas victim2024-06-07
Cencora, Inc., a third-party service provider for Pfizer Inc., notified consumers of a data security incident discovered on February 21, 2024. Personal information, including names, addresses, dates of birth, health diagnoses, and prescriptions, was exfiltrated. Cencora engaged law enforcement and cybersecurity experts, contained the incident, and provided 24 months of credit monitoring. No evidence of fraud was found at the time of notification.
- FEDERALSEC 10-K Item 1Cas victim2024-02-22
Pfizer Inc.'s 2023 Form 10-K Item 1C cybersecurity disclosure. As of the filing date, Pfizer states it is not aware of any cybersecurity incidents that have materially affected or are reasonably likely to materially affect the company. The disclosure describes the company's ERM-integrated cybersecurity program, governance structure (Audit Committee and CISO), and risk awareness of threats from nation-states, organized crime, insiders, and activists targeting IP, financial resources, and personal information.
- ⛰️New Hampshire State AGas victim2007-08-24
Pfizer Inc notified approximately 34,000 individuals (colleagues, former employees, and healthcare professionals) of a data breach in New Hampshire. An internal employee wrongfully removed confidential data from a Pfizer computer system in late 2006. Pfizer discovered the breach on July 10, 2007. Exposed data included names, SSNs/TINs, addresses, phone numbers, credit card/bank account numbers, and government IDs. Pfizer notified law enforcement, state Attorneys General, and credit bureaus, and provided two years of free identity theft protection via IDS.