INTERNATIONAL BUSINESS MACHINES CORP
ent_019fa1fa7f94ab92d7c5af356a553dfe
Disclosures
6
SEC 10-K Item 1C · State AG · 5 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
10,000
as filed · State AG DE
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- INTERNATIONAL BUSINESS MACHINES CORP
- Normalized
- international business machines— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- VGRQXHF3J8VDLUA7XE92
- SEC EDGAR CIK
- 0000051143
- Domain
- ibm.com
Disclosure history (6)newest first
- FEDERALSEC 10-K Item 1Cas victim2026-02-24
This document is IBM's 2025 Annual Report (Exhibit 13, Report of Financials), filed with the SEC on February 24, 2026, as part of IBM's Form 10-K. It contains IBM's Management Discussion and financial results for the year ended December 31, 2025. No cybersecurity breach or incident is described in the extracted portion of this document.
- 💎Delaware State AGas reporting2023-09-22
Johnson & Johnson Health Care Systems, Inc. (Janssen) experienced unauthorized access to a database supporting the Janssen CarePath patient support platform. The database was managed by third-party provider IBM. The incident involved a technical method allowing unauthorized access, identified on August 2, 2023. Affected data included names and potentially other personal information, though SSNs and financial account numbers were explicitly excluded. IBM and Janssen remediated the vulnerability and augmented security controls. Affected individuals were offered one year of credit monitoring. The notice covers residents of multiple states, including Delaware, New York, and Maryland.
- 🦬Montana State AGas victim2023-09-22
International Business Machines Corporation reported a data breach to the Montana Attorney General. The breach was reported on 2023-09-22. The breach occurred on 8/2/2023. 9,585 Montana residents were affected.
- 💎Delaware State AGas reporting2023-09-22
Johnson & Johnson Health Care Systems, Inc. (Janssen) notified IBM, its service provider, of unauthorized access to the Janssen CarePath database. IBM and a third-party database provider remediated the technical vulnerability and conducted an investigation. The incident, discovered on August 2, 2023, potentially exposed names and government identifiers (e.g., SSN) for approximately 10,000 Rhode Island residents. No financial account or SSN data was in the database. Affected individuals were offered one year of credit monitoring.
- 🐻California State AGas victim2023-09-22
IBM disclosed unauthorized access to a database supporting the Janssen CarePath patient support platform. IBM identified the unauthorized access on August 2, 2023, after Janssen notified IBM of a technical method allowing access. IBM remediated the issue and augmented security controls. Affected data may include names and health-related information, but not SSNs or financial account data. IBM offered one year of credit monitoring.
- 🍁Vermont State AGas reporting2023-09-15
IBM notified Johnson & Johnson Health Care Systems, Inc. (Janssen) of unauthorized access to the Janssen CarePath database. Access was discovered on August 2, 2023. The scope of access is undetermined. Data potentially exposed includes names and other PII; SSNs and financial data were not in the database. IBM remediated the vulnerability and offered one year of credit monitoring.