Skip to content

Cencora

Disclosed Feb 27, 20242 years agoConfirmed

SEC filing

Cencora data theft exposes patient health and medication information

Pharmaceutical distributor Cencora (formerly AmerisourceBergen) disclosed in an SEC filing that it learned on February 21, 2024 that data had been exfiltrated from its systems. Patient data it held for drug maker support programs, including names, addresses, birth dates, diagnoses and medications, was taken, and by August it had notified over a million people.

What is known

People affectedNot stated in the sources we have
DisclosedFeb 27, 2024
DiscoveredFeb 21, 2024
AttackHacking
Data exposedNames, Addresses, Dates of birth, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
SEC 8-KtotalFeb 27, 2024
ResearchtotalFeb 27, 2024
SEC 8-KtotalJul 31, 2024
History of this record
  • 2026-09-25 · sector: tech to health · seed source
  • 2026-09-25 · attack: unknown to hacking · seed source
  • 2026-09-25 · data_types: [] to ["names","addresses","dob","health"] · seed source
  • 2026-09-25 · discovered: empty to 2024-02-21 · seed source
  • 2026-09-25 · summary: empty to Pharmaceutical distributor Cencora (formerly AmerisourceBergen) disclosed in an SEC filing that it learned on February 21, 2024 that data had been exfiltrated from its systems. Patient data it held for drug maker support programs, including · seed source
  • 2026-09-25 · title: Material cybersecurity incident reported to the SEC (8-K Item 1.05) to Cencora data theft exposes patient health and medication information · seed source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (SEC 8-K), confirmed by SEC 8-K. Record counts are as reported. Not legal advice.

Everything about Cencora

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.