Incident · 8-K Item 1.05
Cencora reports data exfiltration, later confirming health information was involved
Compiled 2026-09-27 from public records. By the cisonews.net Desk.
Cencora, the pharmaceutical distributor formerly known as AmerisourceBergen, told investors on February 27, 2024 that data had been exfiltrated from its information systems and that some of it might contain personal information. The company learned of the exfiltration on February 21, six days before filing.
First filing
Cencora said its systems stayed operational and the incident had not materially affected operations.
July 2024 amendment
Five months later, the 8-K/A reported that more data had been taken than first identified. Review of most of that data confirmed personally identifiable information and protected health information, most of it held by a subsidiary that provides patient support services. Cencora said notifications had gone out for the data reviewed so far and that it did not expect a material financial impact.
Not stated
Cencora's two filings do not give the number of individuals notified, name the subsidiary, or say how the data left its network.
Sources
- 2024-02-27 · ACencora, Inc., Form 8-K (SEC EDGAR), published February 27, 2024
- 2024-07-31 · ACencora, Inc., Form 8-K/A (SEC EDGAR), published July 31, 2024
Tier A: the organization itself, a regulator or SEC EDGAR. Tier B: established press. Each fact on this page carries its supporting passage in the page source.
See an error? Corrections are made on the page and logged on the corrections page. Send them through contact.