BRISTOL-MYERS SQUIBB COMPANY
ent_019e87892f2660949d976488e81bee72
Bristol Myers Squibb is a global biopharmaceutical company that discovers, develops, and delivers innovative medicines for patients with serious diseases, including cancer, immunology, and cardiovascular conditions.
AI-summarized from indexed web sources · Princeton, New Jersey · 2026-08-12 · source
Disclosures
15
Leak Site · State AG · 9 jurisdictions
Multi-filing incidents
4
incidents joining 2+ filings here
Max affected reported
78,516
as filed · State AG IN
Leak-site claims
2
unverified actor claims
Identity resolution
- Canonical name
- BRISTOL-MYERS SQUIBB COMPANY
- Normalized
- bristol myers squibb— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- HLYYNH7UQUORYSJQCN42
- SEC EDGAR CIK
- 0000014272
- Domain
- bms.com
Disclosure history (15)newest first
- GLOBALLeak Siteas victim2026-04-27
Pharmaceutical company. personal data - 302 lines
- GLOBALLeak Siteas victim2024-12-09
Pharmaceutical company. personal data - 302 lines
- Washington State AGas victim2024-05-17
Cencora, Inc. and its affiliate Lash Group reported a cyberattack affecting Bristol Myers Squibb patient support programs. Data exfiltrated included names, addresses, DOB, and health diagnoses. 34,644 Washington residents affected. Incident discovered Feb 21, 2024; notices sent May 17, 2024. Credit monitoring offered.
- Vermont State AGas victim2024-05-17
Cencora, Inc. notified Bristol Myers Squibb Company and the Bristol Myers Squibb Patient Assistance Foundation of a data security incident discovered on Feb 21, 2024. Personal information including names, addresses, DOBs, health diagnoses, and medications was exfiltrated from Cencora's systems. Cencora engaged law enforcement and cybersecurity experts, offered 24 months of credit monitoring, and is reinforcing security protocols.
- California State AGas reporting2024-05-17
Cencora, Inc. and its Lash Group affiliate reported that on February 21, 2024, data was exfiltrated from Cencora's information systems, including personal information of patients enrolled in Bristol Myers Squibb and BMS Patient Assistance Foundation programs. Potentially affected data included name, address, date of birth, health diagnosis, and medications/prescriptions. Cencora engaged cybersecurity experts, law enforcement, and outside counsel. Notification letters dated May 17, 2024 were sent to affected individuals with offers of 24-month Experian identity monitoring.
- Indiana State AGas victim2024-05-17
Bristol Myers Squibb Co and Bristol Myers Squibb Patient Assistance Foundation reported a data breach to the Indiana Attorney General. The breach occurred on 2024-02-21 and was reported on 2024-05-17. 78,516 Indiana residents were affected.
- Montana State AGas victim2024-05-17
Cencora, Inc. and its affiliate Lash Group notified Montana residents of a data security incident involving personal information of patients enrolled in Bristol Myers Squibb patient support programs. Cencora discovered unauthorized exfiltration of data on February 21, 2024. Affected data included names, addresses, dates of birth, health diagnoses, and medications. Cencora engaged law enforcement and cybersecurity experts, and is offering 24 months of credit monitoring.
- Delaware State AGas victim2024-05-17
Cencora, Inc. notified Bristol Myers Squibb Company patients that on February 21, 2024, data was exfiltrated from Cencora's information systems. The incident potentially affected personal information including names, addresses, dates of birth, health diagnoses, and medications. Cencora took containment steps, engaged law enforcement and cybersecurity experts, and is offering 24 months of credit monitoring through Experian. No evidence of misuse was found at the time of notification.
- Massachusetts State AGas victim2023-07-05
Bristol Myers Squibb reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-07-05. 14 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2023-07-03
Bristol Myers Squibb notified New Hampshire AG of a MOVEit vulnerability exploitation. Unauthorized access occurred as early as May 27, 2023. Data of 5 NH residents, including SSNs and names, was exfiltrated. BMS engaged law enforcement, patched the vulnerability, and offered 24 months of credit monitoring.
- Washington State AGas victim2023-06-30
Bristol Myers Squibb disclosed a cybersecurity incident involving the MOVEit SFTP tool, a third-party vendor product. Unauthorized access occurred as early as May 27, 2023, discovered on May 31, 2023. The breach affected up to 2,231 Washington residents, exposing names, DOBs, contact details, employment status, and SSNs for 45 individuals. Notices were sent starting June 29, 2023, offering 24 months of credit monitoring.
- Montana State AGas victim2023-06-29
Bristol Myers Squibb notified Montana residents of a data breach involving the MOVEit transfer tool by Progress Software. Unauthorized access occurred as early as May 27, 2023, discovered on June 1, 2023. Data accessed included SSNs and HR info. BMS engaged law enforcement, third-party experts, and offered 24 months of credit monitoring.
- Massachusetts State AGas victim2009-12-09
Bristol-Myers Squibb Company reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2009-12-09. 4 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2008-07-14
Bristol-Myers Squibb Company reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2008-07-14. 1,921 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2008-07-11
Bristol-Myers Squibb Company notified the New Hampshire Attorney General that a backup data tape containing employee and dependent PII (including SSNs, bank account numbers, and employment data) was stolen during transport. The incident was discovered on June 4, 2008. Approximately 458 New Hampshire residents were affected. BMS offered one year of free credit monitoring and identity theft insurance.
Supply-chain cascadesreviewed and confirmed
- BRISTOL-MYERS SQUIBB COMPANY’s filing is one of at least 8 in the CENCORA, INC. supply-chain incident (2024).
Subsidiary disclosures (1)filed by group companies
◈ These filings were made by or about subsidiaries of BRISTOL-MYERS SQUIBB COMPANY — not by BRISTOL-MYERS SQUIBB COMPANY itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.