ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

Cencora, a company building on the legacy of AmerisourceBergen, is a leading global pharmaceutical solutions organization centered on improving the lives of people and animals around the world. We connect manufacturers, providers, and patients to ensure that anyone can get the therapies they need, where and when they need them. We also help our partners bring their innovations to patients more efficiently to accelerate positive outcomes. Becoming Cencora has allowed us to combine all the companies and services of AmerisourceBergen. Now, as a unified and internationally inclusive brand, we’re continuing to invest in and focus on our core pharmaceutical distribution business, while also growing our platform of pharma and biopharma services to support pharmaceutical innovation and access. Our 51,000 worldwide team members are shaping the future of healthcare through the power of our purpose: We are united in our responsibility to create healthier futures. AmerisourceBergen, now Cencora, is ranked #10 on the Fortune 500 and #24 on the Global Fortune 500 with more than $290 billion in annual revenue.

Cencora A.I CyberSecurity Scoring

Cencora

Company Details

Linkedin ID:

cencoraglobal

Employees number:

25,517

Number of followers:

192,720

NAICS:

62

Industry Type:

Hospitals and Health Care

Homepage:

cencora.com

IP Addresses:

81

Company ID:

CEN_2988286

Scan Status:

Completed

AI scoreCencora Risk Score (AI oriented)

Between 750 and 799

https://images.rankiteo.com/companyimages/cencoraglobal.jpeg
Cencora Hospitals and Health Care
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreCencora Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/cencoraglobal.jpeg
Cencora Hospitals and Health Care
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

Cencora Company CyberSecurity News & History

Past Incidents
1
Attack Types
1
EntityTypeSeverityImpactSeenBlog DetailsIncident DetailsView
Cencora (COR)Breach8542/2024
Rankiteo Explanation :
Attack with significant impact with customers data leaks

Description: In February 2024, Cencora, a US pharmaceutical giant with over $290 billion in annual revenue and 51,000 employees, suffered a major **data breach** targeting its subsidiary, **World Courier Group**. Hackers infiltrated the company’s systems and exfiltrated **sensitive personal information** of **over 1.4 million individuals**, including **current and former employees** (names, addresses, dates of birth, Social Security numbers) as well as data linked to **27 pharmaceutical and biotechnology partners**. The breach led to a **class-action lawsuit**, with Cencora agreeing to compensate affected individuals up to **$5,000 per person**, capped at **$5 million total** for documented losses. The incident exposed critical internal and partner-related data, posing significant **financial, reputational, and operational risks** to the company and its stakeholders.

Cencora (COR)
Breach
Severity: 85
Impact: 4
Seen: 2/2024
Blog:
Rankiteo Explanation
Attack with significant impact with customers data leaks

Description: In February 2024, Cencora, a US pharmaceutical giant with over $290 billion in annual revenue and 51,000 employees, suffered a major **data breach** targeting its subsidiary, **World Courier Group**. Hackers infiltrated the company’s systems and exfiltrated **sensitive personal information** of **over 1.4 million individuals**, including **current and former employees** (names, addresses, dates of birth, Social Security numbers) as well as data linked to **27 pharmaceutical and biotechnology partners**. The breach led to a **class-action lawsuit**, with Cencora agreeing to compensate affected individuals up to **$5,000 per person**, capped at **$5 million total** for documented losses. The incident exposed critical internal and partner-related data, posing significant **financial, reputational, and operational risks** to the company and its stakeholders.

Ailogo

Cencora Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for Cencora

Incidents vs Hospitals and Health Care Industry Average (This Year)

No incidents recorded for Cencora in 2025.

Incidents vs All-Companies Average (This Year)

No incidents recorded for Cencora in 2025.

Incident Types Cencora vs Hospitals and Health Care Industry Avg (This Year)

No incidents recorded for Cencora in 2025.

Incident History — Cencora (X = Date, Y = Severity)

Cencora cyber incidents detection timeline including parent company and subsidiaries

Cencora Company Subsidiaries

SubsidiaryImage

Cencora, a company building on the legacy of AmerisourceBergen, is a leading global pharmaceutical solutions organization centered on improving the lives of people and animals around the world. We connect manufacturers, providers, and patients to ensure that anyone can get the therapies they need, where and when they need them. We also help our partners bring their innovations to patients more efficiently to accelerate positive outcomes. Becoming Cencora has allowed us to combine all the companies and services of AmerisourceBergen. Now, as a unified and internationally inclusive brand, we’re continuing to invest in and focus on our core pharmaceutical distribution business, while also growing our platform of pharma and biopharma services to support pharmaceutical innovation and access. Our 51,000 worldwide team members are shaping the future of healthcare through the power of our purpose: We are united in our responsibility to create healthier futures. AmerisourceBergen, now Cencora, is ranked #10 on the Fortune 500 and #24 on the Global Fortune 500 with more than $290 billion in annual revenue.

Loading...
similarCompanies

Cencora Similar Companies

BayCare Health System

BayCare is a leading not-for-profit academic health care system that connects individuals and families to a wide range of services at 16 hospitals, including a children’s hospital, and hundreds of other convenient locations throughout the Tampa Bay and central Florida regions. The system is West Cen

Hospital for Special Surgery

HSS is the world’s leading academic medical center focused on musculoskeletal health. At its core is Hospital for Special Surgery, nationally ranked No. 1 in orthopedics (for the 16th consecutive year), No. 3 in rheumatology by U.S. News & World Report (2025-2026), and the best pediatric orthopedic

Allegheny Health Network

Allegheny Health Network is an integrated health care delivery system serving the greater Western Pennsylvania region. More than 2,600 physicians and 21,000 employees serve the system's 14 hospitals as well as its ambulatory medical and surgery centers, Health + Wellness Pavilions, and hundreds of p

Johnson & Johnson MedTech

At Johnson & Johnson MedTech, we are working to solve the world’s most pressing healthcare challenges through innovations at the intersection of biology and technology. With deep expertise in surgery, orthopaedics, cardiovascular, and vision, we design healthcare solutions that are smarter, less inv

DaVita Kidney Care

DaVita means “to give life,” reflecting our proud history as leaders in dialysis—an essential, life-sustaining treatment for those living with end stage kidney disease (ESKD). Today, our mission is to minimize the devastating impacts of kidney disease across the full spectrum of kidney health care.

Beth Israel Deaconess Medical Center

Beth Israel Deaconess Medical Center (BIDMC) is part of Beth Israel Lahey Health, a new health care system that brings together academic medical centers and teaching hospitals, community and specialty hospitals, more than 4,000 physicians and 35,000 employees in a shared mission to expand access to

NHG Health

NHG Health is a leading public healthcare provider in Singapore recognised for its quality clinical care and its commitment in enabling healthier lives through preventive health, innovative solutions and person-centred programmes tailored to every life stage. Our integrated health system, which span

Memorial Healthcare System

Be at the heart of exceptional care. Team MHS Florida is an award-winning group of friends and colleagues at one of the largest not-for-profit health systems in the nation. We're 17,000 strong, advancing towards a brighter future together. We're passionate about the work we do, delivering deep, pe

After the acquisition of the Capio Group in 2018, Ramsay Santé has become Europe's leading private hospital and primary care companies. The group now has 36,000 employees and works with nearly 8,600 private practitioners. Present in 5 countries, France, Sweden, Norway, Denmark and Italy, the group

newsone

Cencora CyberSecurity News

September 26, 2025 07:00 AM
Pennsylvania Firm Handing Out $5,000 per Person To Settle Lawsuit Over Data Breach That Exposed Social Security Numbers of at Least 1,400,000 People

A US pharmaceutical giant has agreed to compensate those who were impacted by a major 2024 data breach. According to the newly updated...

August 11, 2025 07:00 AM
Cencora & The Lash Group Settle Data Breach Litigation for $40 Million

Cencora, The Lash Group, and their affiliates have agreed to pay $40 million to settle class action data breach litigation over a February...

March 18, 2025 02:57 AM
27 Pharma Companies Breached Via US Pharmaceutical Giant Cencora

Cencora, Inc. has recently notified affected individuals that their personal and sensitive medical details were stolen in a cyberattack.

January 27, 2025 08:00 AM
CISOs Boost Crisis Simulation Budgets Amid High-Profile Cyber-Attacks

Most CISOs plan to enhance their crisis simulation capabilities in 2025 to better prepare for potential full-scale cyber crises, according to a new study by...

January 16, 2025 08:00 AM
The mystery of the $75M ransom payment to Dark Angels

Questions remain about how a public company can pay $75 million to the Dark Angels ransomware gang without any disclosures to shareholders...

December 24, 2024 08:00 AM
These are the cybersecurity stories we were jealous of in 2024

Here are our favorite cybersecurity stories of this year written by our friends at rival outlets.

October 14, 2024 07:00 AM
The biggest data breaches in 2024: 1 billion stolen records and rising

Some of the largest, most damaging breaches of 2024 already account for over a billion stolen records. Plus, some special shout-outs.

September 19, 2024 07:00 AM
Cencora Faces Criticism After Paying Rp1.15 Trillion Ransom In Bitcoin Due To Cyber Attack

Cencora faced criticism after paying a ransom of Rp1.15 trillion in bitcoin due to cyber attacks (Photo; Doc. Techcrunch).

September 19, 2024 07:00 AM
Cencora Pays Record $75M Ransom in Major Cyberattack

Cencora paid $75 million ransom following a cyberattack, marking the largest extortion payment ever, with the breach involving sensitive...

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

Cencora CyberSecurity History Information

Official Website of Cencora

The official website of Cencora is https://www.cencora.com/.

Cencora’s AI-Generated Cybersecurity Score

According to Rankiteo, Cencora’s AI-generated cybersecurity score is 788, reflecting their Fair security posture.

How many security badges does Cencora’ have ?

According to Rankiteo, Cencora currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does Cencora have SOC 2 Type 1 certification ?

According to Rankiteo, Cencora is not certified under SOC 2 Type 1.

Does Cencora have SOC 2 Type 2 certification ?

According to Rankiteo, Cencora does not hold a SOC 2 Type 2 certification.

Does Cencora comply with GDPR ?

According to Rankiteo, Cencora is not listed as GDPR compliant.

Does Cencora have PCI DSS certification ?

According to Rankiteo, Cencora does not currently maintain PCI DSS compliance.

Does Cencora comply with HIPAA ?

According to Rankiteo, Cencora is not compliant with HIPAA regulations.

Does Cencora have ISO 27001 certification ?

According to Rankiteo,Cencora is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of Cencora

Cencora operates primarily in the Hospitals and Health Care industry.

Number of Employees at Cencora

Cencora employs approximately 25,517 people worldwide.

Subsidiaries Owned by Cencora

Cencora presently has no subsidiaries across any sectors.

Cencora’s LinkedIn Followers

Cencora’s official LinkedIn profile has approximately 192,720 followers.

NAICS Classification of Cencora

Cencora is classified under the NAICS code 62, which corresponds to Health Care and Social Assistance.

Cencora’s Presence on Crunchbase

No, Cencora does not have a profile on Crunchbase.

Cencora’s Presence on LinkedIn

Yes, Cencora maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/cencoraglobal.

Cybersecurity Incidents Involving Cencora

As of December 11, 2025, Rankiteo reports that Cencora has experienced 1 cybersecurity incidents.

Number of Peer and Competitor Companies

Cencora has an estimated 30,928 peer or competitor companies worldwide.

What types of cybersecurity incidents have occurred at Cencora ?

Incident Types: The types of cybersecurity incidents that have occurred include Breach.

How does Cencora detect and respond to cybersecurity incidents ?

Detection and Response: The company detects and responds to cybersecurity incidents through an communication strategy with data breach notification letters (e.g., dated 2024-12-12), communication strategy with settlement portal for claims..

Incident Details

Can you provide details on each incident ?

Incident : data breach

Title: Cencora (formerly AmerisourceBergen) Data Breach (2024)

Description: A major data breach at Cencora (COR) in 2024 exposed personal information of over 1.4 million individuals, including employees and partners from 27+ pharmaceutical and biotechnology companies. The breach involved exfiltration of sensitive data such as names, addresses, dates of birth, and Social Security numbers. A class-action lawsuit followed, leading to a settlement offering up to $5,000 per affected individual (capped at $5M total).

Date Publicly Disclosed: 2024-02-01

Type: data breach

What are the most common types of attacks the company has faced ?

Common Attack Types: The most common types of attacks the company has faced is Breach.

Impact of the Incidents

What was the impact of each incident ?

Incident : data breach CEN2702127093025

Data Compromised: Personal information (names, addresses, dob, ssn), Sensitive private information

Systems Affected: World Courier Group systemssubsidiaries of Cencora

Brand Reputation Impact: High (class-action lawsuit, public disclosure of 1.4M+ affected individuals)

Legal Liabilities: class-action lawsuitsettlement payments up to $5M

Identity Theft Risk: High (SSN and PII exposed)

What types of data are most commonly compromised in incidents ?

Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Personally Identifiable Information (Pii), Employee Records, Partner Company Data and .

Which entities were affected by each incident ?

Incident : data breach CEN2702127093025

Entity Name: Cencora (COR)

Entity Type: public company

Industry: pharmaceutical distribution

Location: Pennsylvania, USA

Size: 51,000 employees, $290B annual revenue

Customers Affected: 1,400,000+ individuals (including employees and partners)

Incident : data breach CEN2702127093025

Entity Name: World Courier Group

Entity Type: subsidiary

Industry: logistics/pharmaceutical supply chain

Incident : data breach CEN2702127093025

Entity Name: 27+ partner pharmaceutical and biotechnology companies

Entity Type: business partners

Industry: pharmaceutical, biotechnology

Response to the Incidents

What measures were taken in response to each incident ?

Incident : data breach CEN2702127093025

Communication Strategy: data breach notification letters (e.g., dated 2024-12-12)settlement portal for claims

Data Breach Information

What type of data was compromised in each breach ?

Incident : data breach CEN2702127093025

Type of Data Compromised: Personally identifiable information (pii), Employee records, Partner company data

Number of Records Exposed: 1,400,000+

Sensitivity of Data: High (includes SSN, DOB, addresses)

Personally Identifiable Information: namesaddressesdates of birthSocial Security numbers

Ransomware Information

Was ransomware involved in any of the incidents ?

Incident : data breach CEN2702127093025

Data Exfiltration: True

Regulatory Compliance

Were there any regulatory violations and fines imposed for each incident ?

Incident : data breach CEN2702127093025

Legal Actions: class-action lawsuit, settlement agreement,

How does the company ensure compliance with regulatory requirements ?

Ensuring Regulatory Compliance: The company ensures compliance with regulatory requirements through class-action lawsuit, settlement agreement, .

References

Where can I find more information about each incident ?

Incident : data breach CEN2702127093025

Source: The Daily Hodl

Incident : data breach CEN2702127093025

Source: Cencora Data Breach Settlement Portal

Incident : data breach CEN2702127093025

Source: Cencora Data Breach Notification Letter (2024-12-12)

Where can stakeholders find additional resources on cybersecurity best practices ?

Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: The Daily Hodl, and Source: Cencora Data Breach Settlement Portal, and Source: Cencora Data Breach Notification Letter (2024-12-12).

Investigation Status

How does the company communicate the status of incident investigations to stakeholders ?

Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Data Breach Notification Letters (E.G., Dated 2024-12-12) and Settlement Portal For Claims.

Stakeholder and Customer Advisories

Were there any advisories issued to stakeholders or customers for each incident ?

Incident : data breach CEN2702127093025

Customer Advisories: settlement claims process for affected individuals

What advisories does the company provide to stakeholders and customers following an incident ?

Advisories Provided: The company provides the following advisories to stakeholders and customers following an incident: were Settlement Claims Process For Affected Individuals and .

Initial Access Broker

How did the initial access broker gain entry for each incident ?

Incident : data breach CEN2702127093025

High Value Targets: Employee Pii, Partner Company Data,

Data Sold on Dark Web: Employee Pii, Partner Company Data,

Additional Questions

Incident Details

What was the most recent incident publicly disclosed ?

Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2024-02-01.

Impact of the Incidents

What was the most significant data compromised in an incident ?

Most Significant Data Compromised: The most significant data compromised in an incident were personal information (names, addresses, DOB, SSN), sensitive private information and .

What was the most significant system affected in an incident ?

Most Significant System Affected: The most significant system affected in an incident was World Courier Group systemssubsidiaries of Cencora.

Data Breach Information

What was the most sensitive data compromised in a breach ?

Most Sensitive Data Compromised: The most sensitive data compromised in a breach were sensitive private information, personal information (names, addresses, DOB and SSN).

What was the number of records exposed in the most significant breach ?

Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 1.4M.

Regulatory Compliance

What was the most significant legal action taken for a regulatory violation ?

Most Significant Legal Action: The most significant legal action taken for a regulatory violation was class-action lawsuit, settlement agreement, .

References

What is the most recent source of information about an incident ?

Most Recent Source: The most recent source of information about an incident are Cencora Data Breach Settlement Portal, The Daily Hodl and Cencora Data Breach Notification Letter (2024-12-12).

Stakeholder and Customer Advisories

What was the most recent customer advisory issued ?

Most Recent Customer Advisory: The most recent customer advisory issued was an settlement claims process for affected individuals.

cve

Latest Global CVEs (Not Company-Specific)

Description

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through 17.0.9 have a weak default password. By default, this is a 6 digit numeric value which can be brute forced. (This is the app_password parameter). Depending on local configuration, this password could be the extension, voicemail, user manager, DPMA or EPM phone admin password. This issue is fixed in versions 16.0.96 and 17.0.10.

Risk Information
cvss4
Base: 6.9
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool executes arbitrary SQL provided by the caller using PDO::prepare() + execute() without semantic restrictions. This is consistent with the name (“write tool”), but in an LLM/agent context it becomes a high-risk capability: prompt injection or indirect prompt manipulation can cause execution of destructive queries such as DROP TABLE, TRUNCATE, DELETE, ALTER, or privilege-related statements (subject to DB permissions). Deployments that expose an agent with MySQLWriteTool enabled to untrusted input and/or run the tool with a DB user that has broad privileges are impacted. This issue is fixed in version 2.8.12.

Risk Information
cvss3
Base: 9.4
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Description

Neuron is a PHP framework for creating and orchestrating AI Agents. Versions 2.8.11 and below use MySQLSelectTool, which is vulnerable to Read-Only Bypass. MySQLSelectTool is intended to be a read-only SQL tool (e.g., for LLM agent querying, however, validation based on the first keyword (e.g., SELECT) and a forbidden-keyword list does not block file-writing constructs such as INTO OUTFILE / INTO DUMPFILE. As a result, an attacker who can influence the tool input (e.g., via prompt injection through a public agent endpoint) may write arbitrary files to the DB server if the MySQL/MariaDB account has the FILE privilege and server configuration permits writes to a useful location (e.g., a web-accessible directory). This issue is fixed in version 2.8.12.

Risk Information
cvss3
Base: 8.2
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Description

Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may arise from concurrent requests using the ApiClient class. This could cause a status code or response header from one request’s response to influence another request’s response. This issue is fixed in version 20.0.1.

Risk Information
cvss3
Base: 8.4
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L
Description

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache for the request results. This issue is fixed in versions 4.11.2 and 4.12.1.

Risk Information
cvss3
Base: 5.4
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=cencoraglobal' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge