
American pharmaceutical sourcing and distributions company Cencora said that patients’ protected health information and sensitive personal information was compromised in a data security incident the company suffered earlier this year.
In a data breach notice filed with the state authorities of Massachusetts, Cencora, formerly known as AmerisourceBergen, said that on February 21, it became aware of a data security incident where threat actors infiltrated its internal network and stole sensitive personal data stored in a company database.
In a recent filing with the United States Securities and Exchange Commission, Cencora said its investigation into the data security incident has revealed that the protected health information and sensitive personal information of patients were accessed by hackers.
“Through that investigation, the Company learned that additional data, beyond what was initially identified, had been exfiltrated. The Company has identified and completed its review of most of the exfiltrated data (the "Data").
“This review has confirmed that the Data included personally identifiable information ("PII") and protected health information ("PHI") of individuals, most of which is maintained by a Company subsidiary that provides patient support services,” reads the SEC filing.
Cencora added that the cyber attack has been contained and the company has taken remediation efforts, including strengthening its surveillance of cybersecurity threats, to avoid such incidents in the future.
The data breach was first identified by cyber security researcher Dominic Alvieri in February. He said in a tweet that the Lorenz ransomware gang resurfaced by targeting the pharmaceutical company after laying low for a while. “AmerisourceBergen subsidiary is being accessed through a Lorenz back door,” he tweeted.
The files posted by the Lorenz gang belonged to AmerisourceBergen and MWI Animal Health, a subsidiary whose internal network was infiltrated by the threat actor. While the files were published recently, the threat actor’s post dates back to November 1, 2023, indicating that the security incident took place a few months ago.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543