logo

Cencora data breach exposes US patient info from 11 drug companies

ID: f2cb3d5e-348f-5582-bcc6-4bae3533acf1

STIX ID: report--f2cb3d5e-348f-5582-bcc6-4bae3533acf1

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-05-24

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Cencora (formerly AmerisourceBergen) experienced a February 2024 cyberattack that allowed unauthorized parties to access and exfiltrate personal and health-related data used in patient support programs for numerous major pharmaceutical companies; at least eleven large firms submitted breach notifications naming exposed fields including full name, address, health diagnoses, medications and prescriptions. Cencora concluded an internal investigation on April 10, 2024, is offering two years of Experian credit monitoring to affected individuals, and there is currently no evidence the stolen data has been publicly posted or used for fraud.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.