PFIZER INC.
ent_019e44ea4ff529854e5cd93730dc498e
Disclosures
13
State AG · 7 jurisdictions
Multi-filing incidents
4
incidents joining 2+ filings here
Max affected reported
34,000
as filed · State AG NH
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- PFIZER INC.
- Normalized
- pfizer— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 765LHXWGK1KXCLTFYQ30
- SEC EDGAR CIK
- 0000078003
- Domain
- pfizer.com
Disclosure history (13)newest first
- Montana State AGas victim2024-06-07
Cencora, Inc. notified Montana residents of a data security incident affecting personal and health information of individuals enrolled in Pfizer Inc.'s patient support programs via Lash Group. Cencora discovered unauthorized exfiltration on Feb 21, 2024. Data included names, addresses, DOB, and health diagnoses. Cencora engaged law enforcement and forensic experts, offering 24 months of credit monitoring.
- California State AGas victim2024-06-07
Cencora, Inc. and its Lash Group affiliate, a third-party partner supporting Pfizer Inc.'s patient support programs, experienced a data exfiltration incident detected on February 21, 2024. Personal information including names, addresses, dates of birth, health diagnoses, and medications/prescriptions was potentially affected. On April 10, 2024, Cencora confirmed affected individuals. Cencora launched an investigation with law enforcement and cybersecurity experts and is offering 24 months of Experian credit monitoring.
- Indiana State AGas victim2024-06-07
Pfizer Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2024-02-21 and was reported on 2024-06-07. 2,872 Indiana residents were affected.
- Washington State AGas victim2024-06-07
The Lash Group, a third-party service provider for Pfizer Inc., disclosed a cybersecurity incident on February 21, 2024, involving the exfiltration of personal information including names, addresses, dates of birth, health diagnoses, and medications. The incident was reported to the Washington Attorney General on June 7, 2024, affecting 2,650 Washington residents. The Lash Group engaged forensic experts and offered credit monitoring to affected individuals.
- Vermont State AGas victim2024-06-07
Cencora, Inc., a third-party service provider for Pfizer Inc., notified consumers of a data security incident discovered on February 21, 2024. Personal information, including names, addresses, dates of birth, health diagnoses, and prescriptions, was exfiltrated. Cencora engaged law enforcement and cybersecurity experts, contained the incident, and provided 24 months of credit monitoring. No evidence of fraud was found at the time of notification.
- Massachusetts State AGas victim2021-08-17
Pfizer Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-08-17. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2011-06-15
Pfizer Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2011-06-15. 70 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2009-05-11
Pfizer Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2009-05-11. 19 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2009-05-07
Pfizer Inc reported the inadvertent disposal of a backup hard drive containing the names and Social Security numbers of approximately 3 New Hampshire residents. The drive was discarded in trash on March 26, 2009, by an employee. Pfizer engaged forensic experts, notified affected individuals, and offered two years of credit monitoring and identity theft insurance. Remediation steps included limiting data on devices and encrypting laptops.
- Massachusetts State AGas victim2008-03-24
Pfizer, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2008-03-24. 15 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2008-03-19
Pfizer Inc reported the theft of a contractor's laptop on February 7, 2008, containing personal information for approximately 800 individuals, including 3 New Hampshire residents. Data exposed included names, credit card numbers, expiration dates, addresses, phone numbers, and email addresses. No SSNs or PINs were exposed. Pfizer notified police, credit bureaus, and affected individuals, offering 2 years of credit protection services.
- New Hampshire State AGas victim2007-08-24
Pfizer Inc notified approximately 34,000 individuals (colleagues, former employees, and healthcare professionals) of a data breach in New Hampshire. An internal employee wrongfully removed confidential data from a Pfizer computer system in late 2006. Pfizer discovered the breach on July 10, 2007. Exposed data included names, SSNs/TINs, addresses, phone numbers, credit card/bank account numbers, and government IDs. Pfizer notified law enforcement, state Attorneys General, and credit bureaus, and provided two years of free identity theft protection via IDS.
- New Hampshire State AGas victim2007-05-30
Pfizer notified NH AG of a data breach affecting ~17,000 employees. A spouse of an employee installed unauthorized file-sharing software on a work laptop, exposing names and SSNs. Pfizer retrieved the laptop, disabled the software, and engaged Experian for credit monitoring and insurance.
Supply-chain cascadesreviewed and confirmed
- PFIZER INC.’s filing is one of at least 8 in the CENCORA, INC. supply-chain incident (2024).