Data breach at medical giant Cencora exposes info from multiple drug companies

healthcare
(Image credit: Shutterstock)

Almost a dozen pharmaceutical companies, including several major players, have lost sensitive customer data due to a supply chain cyberattack that trickled down from pharma giant Cencora.

In late February 2024, drug wholesale company Cencora (previously known as AmerisourceBergen) filed a Form 8-K with the Securities and Exchange Commission (SEC), reporting a data breach incident, without going into too many details. 

Now, BleepingComputer has found 11 pharmaceutical companies, all submitting almost identical breach notification letters to the California Attorney General’s office, and all claiming a data breach as a result of the Cencora incident.

Identity theft and phishing

The affected companies are Novartis Pharmaceuticals Corporation, Bayer Corporation, AbbVie, Regeneron Pharmaceuticals, Genentech, Incyte Corporation, Sumitomo Pharma America, Acadia Pharmaceuticals, GlaxoSmithKline Group, Endo Pharmaceuticals, and Dendreon Pharmaceuticals.

The companies lost customers’ full names, postal addresses, health diagnoses, medications, and prescriptions. 

At this time, there doesn't appear to be any evidence of data misuse, however, since there is genuine risk of identity theft, phishing, and other forms of attacks, the exposed individuals will be offered two years of free identity protection and credit monitoring through Experian. 

Cencora’s investigation, which apparently concluded in mid-April 2024, found the incident to be a data smash-and-grab, rather than a ransomware attack - so the company does not expect the attack to have a significant effect on its operations or financial status. However, there is always the possibility of a class-action lawsuit, or the EU investigating if there was a breach of GDPR.

Cencora is a pharmacy behemoth with more than 46,000 employees, and roughly $262.2 billion in revenue, in 2023 alone. It is based out of Pennsylvania and operates in some 50 countries around the world. While all 11 of the victims are pharma giants, Novartis can be singled out as one of the world’s biggest companies in the industry, with significant operations in oncology, neuroscience, and immunology.

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
ransomware avast
The biggest addiction treatment provider in the US says it was hit by data breach
healthcare
Over a million clinical records exposed in data breach
Lock on Laptop Screen
United Healthcare data breach may have affected 190 million Americans
ID theft
Over a million patients potentially hit after another US healthcare provider hit by cyberattack
Data breach
Top medical billing firm says data breach hit 360,000 users
security
Ransomware gangs allegedly hit two major US healthcare firms, 300,000 patients have data stolen
Latest in Security
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Google Chrome
Google Chrome security flaw could have let hackers spy on all your online habits
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Latest in News
Xbox Series X and Xbox wireless controller set to a green background
Xbox Insiders are currently testing a new Game Hub feature that looks useful, but I've got mixed feelings about it
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Microsoft Surface Laptop and Surface Pro devices on a table.
Hate Windows 11’s search? Microsoft is fixing it with AI, and that almost makes me want to buy a Copilot+ PC
Oura Ring 4
Activity tracking on Oura Ring is about to get a whole lot better, but I've got bad news about your step count
Google Pixel Buds Pro 2
Cleaned your Pixel Buds Pro 2 recently? If not, you might be getting worse sound
Google Maps on a phone being held in someone's hand
Google Maps is getting two key upgrades, for easier route planning and quicker access to Gemini AI