GlaxoSmithKline Group of Companies
ent_96dfcf7f7959df565ffae8aa
Disclosures
5
State AG · 5 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
21,538
as filed · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- GlaxoSmithKline Group of Companies
- Normalized
- glaxosmithkline group of companies— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- Delaware State AGas victim2024-05-24
Cencora, Inc. notified individuals in multiple states, including Delaware, that personal information (names, addresses, DOB, SSN, health diagnoses, prescriptions) was exfiltrated from its systems on February 21, 2024. The incident involved data related to the GlaxoSmithKline Group of Companies. Cencora took containment steps, engaged law enforcement and cybersecurity experts, and is offering 24 months of credit monitoring via Experian. No evidence of fraud was found at the time of notification.
- Montana State AGas reporting2024-05-24
Cencora, Inc. notified Montana residents of a data security incident discovered on February 21, 2024, where data containing personal information was exfiltrated. The breach potentially affected names, addresses, dates of birth, health diagnoses, and medications. Cencora engaged law enforcement and cybersecurity experts, contained the incident, and offered 24 months of credit monitoring via Experian.
- Washington State AGas victim2024-05-24
The Lash Group, LLC, a third-party service provider for GlaxoSmithKline, reported a cybersecurity incident where data was exfiltrated from its systems. The breach, discovered on February 21, 2024, affected personal and health information of approximately 6,617 Washington residents. The incident involved unauthorized access and data theft, prompting notifications to affected individuals and credit monitoring services.
- Indiana State AGas victim2024-05-24
GlaxoSmithKline Group of Companies GlaxoSmithKline PT Access Prgm FDN reported a data breach to the Indiana Attorney General. The breach occurred on 2024-02-21 and was reported on 2024-05-24. 21,538 Indiana residents were affected.
- Vermont State AGas victim2024-05-24
GlaxoSmithKline Group of Companies was affected by a data breach involving its third-party service provider, Cencora. Cencora learned on Feb 21, 2024 that data had been exfiltrated. Affected data included names, addresses, DOBs, health diagnoses, and medications. Lash Group, a partner, is notifying consumers and offering 24 months of credit monitoring via Experian. No evidence of fraud was found at the time of notice.
Supply-chain cascadesreviewed and confirmed
- GlaxoSmithKline Group of Companies’s filing is one of at least 8 in the CENCORA, INC. supply-chain incident (2024).