Share this article on:
A February attack on a US pharmaceutical solutions company has resulted in almost a dozen drug companies disclosing their own data breaches.
On 21 February, Cencora discovered unauthorised activity on its systems and that data had been exfiltrated.
“As of the date of this filing, the incident has not had a material impact on the company’s operations, and its information systems continue to be operational,” the company said in a 28 February breach notification.
“The company has not yet determined whether the incident is reasonably likely to materially impact the company’s financial condition or results of operations.”
Now, 11 drug companies that partner with Cencora have disclosed data breaches of their own. These include:
According to data breach notifications published by the California Attorney General’s office from the affected companies, the Cencora cyber incident was the catalyst for their own breaches.
The 11 groups have published similar data breach notifications, with heavy input from Cencora affiliate partner Lash Group, which notified the organisations of the incident on 18 April.
“Based on our investigation, personal information was affected, including potentially your first name, last name, address, date of birth, health diagnosis, and/or medications and prescriptions,” reads the Bayer notification.
“There is no evidence that any of this information has been or will be publicly disclosed, or that any information was or will be misused for fraudulent purposes as a result of this incident, but we are communicating this to you so that you can take the steps outlined below to protect yourself.”
Now, the US data breach class action law firm Console & Associates is preparing class actions against the affected companies and has invited those affected to reach out.
“Our data breach lawyers are eager to speak to victims of the Bayer data breach to determine what damages they sustained and what compensation may be available to them,” says the Bayer class action page. There are also pages for Novartis, AbbVie, Genentech and more.
“Victims can file a data breach class action lawsuit if you recently received a NOTICE OF DATA BREACH from Bayer or the Lash Group.”