Data leak β›“ Supply Chain

Cencora (AmerisourceBergen) data breach affecting 11+ pharma companies

πŸ“… 2024-02-21 🏒 Cencora (formerly AmerisourceBergen) patient support platform
Primary Source β†—

Incident Details

Cencora detected a cyberattack on 21 February 2024. Attackers exfiltrated patient data from its patient support program platform used by major pharmaceutical clients including AbbVie, Bayer, Genentech, Incyte, Novartis, and Regeneron, among others β€” eventually totalling 27 pharma companies breached via Cencora’s systems. Stolen data: patient names, postal addresses, dates of birth, health diagnoses, and medication information for 1,430,000+ individuals. No ransomware group claimed responsibility; security researchers believe a ransom was paid silently. $40 million class action settlement reached. Supply chain vector as the pharma companies themselves were not directly breached.

Technical Details

Initial Attack Vector
unknown
Vendor / Product
Cencora (formerly AmerisourceBergen) patient support platform
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2024-02-21 Breach occurred
  2. 2024-02-27 Publicly disclosed
  3. 2024-05-01 Customers notified