Confirmed breach. Intrusion Sep 27, 2023, discovered Oct 14, 2023 — the first regulatory filing landed 33 days later (flagged late). 166,000 individuals reported across the linked filings.
Regulatory clocksSEC✗ SEC 4-day late · 31dWashington✗ WA AG >90dVermont⏱ VT AG >14 bdayMaine⏱ ME AG >30d · 53dCalifornia✓ CA 60-day OK · 34dFull clock table in Litigation Timeline
SEC 8-KState AGConfirmedLifecycle stage 2 of 3: ConfirmedUnverified claimConfirmedEnforcedalphv
2days
Discovery to SEC materiality determination
SEC filing delay
31days
Materiality determination to SEC 8-K filing
Filing span
71days
Time between earliest and latest filing
Not recorded for this incident
Leak precedence — no leak-site claim in this cluster.
Affected (total reported)
166,000
Data types
—
Jurisdictions
8
CA FEDERAL ME MT NH SC VT WA
Linked filings
8
SEC 8-K · State AG
Affected residents by state
per-filing reported counts
SC166,000
WA1,953
MT445
NH104
ME38
State AGs report only their own residents; bars show per-filing counts.
Timeline
Earliest sighting first · deep chronology in Litigation Timeline
8 filings across 8 jurisdictions · Nov 16, 2023 – Jan 26, 2024 · 3 milestones
Breach window
Oct 14, 2023
When the intrusion reportedly occurred, per the linked filings
Breach discoveredletter-grounded
Oct 14, 2023
Reported by SEC 8-K, NEW HAMPSHIRE AG, VERMONT AG, SOUTH CAROLINA AG, MAINE AG, CALIFORNIA AG, WASHINGTON AG filings
Materiality determined
Oct 16, 2023
Registrant determined the incident material — starts the SEC 4-business-day clock
31 days
🇺🇸FEDERALSEC 8-KFirst filinglinked via same-victim cross-source · 100%
Henry Schein, Inc. filed an 8-K (Item 3.01) on Nov 16, 2023, reporting a Nasdaq delisting notice due to late 10-Q filing. The delay was caused by a cybersecurity incident on Oct 14, 2023, which forced the company to shut down operations and take down applications. This filing supplements the initial Oct 16, 2023 disclosure of the incident.
6 State AG filingsNov 16, 2023 – Dec 6, 2023ExpandCollapse
NHMTVTSCCAME
⛰️New Hampshire State AGlinked via same-victim cross-source · 100%
51 days
🌲Washington State AGMost recentlinked via multistate filing link · 95%
Henry Schein, Inc., a business sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2023-10-14 and filed notice on 2024-01-26. 1,953 Washington residents were affected. 104 days elapsed between awareness and notification. 17 days to identify the breach. 52 days to contain the breach.
Affected (this filing): 1,953
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Henry Schein, Inc. notified New Hampshire AG that a cybersecurity incident occurred on or about October 14, 2023, affecting employee personal information. Approximately 104 NH residents were notified. The breach involved unauthorized access to manufacturing and distribution business systems. Response included taking systems offline, engaging forensic experts, notifying law enforcement, and offering credit monitoring.
Affected (this filing): 104
🦬Montana State AGlinked via same-victim cross-source · 100%
Henry Schein, Inc reported a data breach to the Montana Attorney General. The breach was reported on 2023-11-17. The breach occurred on 10/14/2023. 445 Montana residents were affected.
Affected (this filing): 445
🍁Vermont State AGlinked via same-victim cross-source · 100%
Henry Schein, Inc. disclosed a cybersecurity incident affecting its manufacturing and distribution businesses, discovered on October 14, 2023. The breach involved unauthorized access to employee personal information, including names, SSNs, driver's licenses, financial data, and medical history. The company engaged forensic experts, notified law enforcement, and offered 24 months of Experian identity monitoring to affected employees.
VT AG >14 bday
🌴South Carolina State AGlinked via same-victim cross-source · 100%
Henry Schein, Inc. filed a security breach notice with the South Carolina Department of Consumer Affairs on January 14, 2025, regarding a ransomware attack by the BlackCat group that occurred on October 14, 2023. The incident compromised the personal information of approximately 166,000 individuals, including employees and customers, affecting names, Social Security numbers, and financial account data. The company engaged forensic investigators, notified law enforcement, and sent notification letters to affected parties.
Affected (this filing): 166,000
🐻California State AGlinked via same-victim cross-source · 100%
Henry Schein, Inc. notified employees of a cybersecurity incident discovered on October 14, 2023. An unauthorized third party accessed systems containing employee personal information, including names, addresses, SSNs, financial data, and medical history. The company took systems offline, engaged forensic experts, and is offering 24 months of identity monitoring. The investigation is ongoing.
CA 60-day OK · 34d
🦞Maine State AGlinked via same-victim cross-source · 100%
Henry Schein, Inc. reported an external system breach that occurred on September 27, 2023, and was discovered on October 14, 2023. The breach impacted 29,112 individuals, including 38 residents of Maine. The compromised data includes financial account numbers or credit/debit card numbers along with associated access codes or PINs. Affected individuals were notified starting on November 17, 2023, and were offered 24 months of identity theft and credit monitoring services from Experian.