Cencora discloses a material cybersecurity incident
What the filing says
On February 21, 2024, Cencora, Inc. (the "Company"), learned that data from its information systems had been exfiltrated, some of which may contain personal information. Upon initial detection of the unauthorized activity, the Company immediately took containment steps and commenced an investigation with the assistance of law enforcement, cybersecurity experts and external counsel. As of the date of this filing, the incident has not had a material impact on the Company's operations, and its information systems continue to be operational.
Timeline
- Amended filing · Jul 31, 00:00 UTC
8-K/A: In the Original Report the Company disclosed that it learned, on February 21, 2024, that data from its information systems had been exfiltrated, some of which may contain personal information. Upon initial detection of the unauthorized activity, the Company immediately took containment steps and commenced an investigation with the assistance of law enforcement, cybersecurity experts and external counsel. Through that investigation, the Company learned that additional data, beyond what was initially identified, had been exfiltrated.
Sources: vendors' own status pages, published postmortems and SEC 8-K Item 1.05 filings, read daily. Times as reported. Logos via logo.dev; trademarks belong to their owners.