Data leak
β Supply Chain
Cencora (AmerisourceBergen) data breach affecting 11+ pharma companies
Primary Source βIncident Details
Cencora detected a cyberattack on 21 February 2024. Attackers exfiltrated patient data from its patient support program platform used by major pharmaceutical clients including AbbVie, Bayer, Genentech, Incyte, Novartis, and Regeneron, among others β eventually totalling 27 pharma companies breached via Cencora’s systems. Stolen data: patient names, postal addresses, dates of birth, health diagnoses, and medication information for 1,430,000+ individuals. No ransomware group claimed responsibility; security researchers believe a ransom was paid silently. $40 million class action settlement reached. Supply chain vector as the pharma companies themselves were not directly breached.
Technical Details
- Initial Attack Vector
- unknown
- Vendor / Product
- Cencora (formerly AmerisourceBergen) patient support platform
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2024-02-21 Breach occurred
- 2024-02-27 Publicly disclosed
- 2024-05-01 Customers notified