Company Details
cencoraglobal
25,517
192,720
62
cencora.com
81
CEN_2988286
Completed

Cencora Company CyberSecurity Posture
cencora.comCencora, a company building on the legacy of AmerisourceBergen, is a leading global pharmaceutical solutions organization centered on improving the lives of people and animals around the world. We connect manufacturers, providers, and patients to ensure that anyone can get the therapies they need, where and when they need them. We also help our partners bring their innovations to patients more efficiently to accelerate positive outcomes. Becoming Cencora has allowed us to combine all the companies and services of AmerisourceBergen. Now, as a unified and internationally inclusive brand, we’re continuing to invest in and focus on our core pharmaceutical distribution business, while also growing our platform of pharma and biopharma services to support pharmaceutical innovation and access. Our 51,000 worldwide team members are shaping the future of healthcare through the power of our purpose: We are united in our responsibility to create healthier futures. AmerisourceBergen, now Cencora, is ranked #10 on the Fortune 500 and #24 on the Global Fortune 500 with more than $290 billion in annual revenue.
Company Details
cencoraglobal
25,517
192,720
62
cencora.com
81
CEN_2988286
Completed
Between 750 and 799

Cencora Global Score (TPRM)XXXX

Description: In February 2024, Cencora, a US pharmaceutical giant with over $290 billion in annual revenue and 51,000 employees, suffered a major **data breach** targeting its subsidiary, **World Courier Group**. Hackers infiltrated the company’s systems and exfiltrated **sensitive personal information** of **over 1.4 million individuals**, including **current and former employees** (names, addresses, dates of birth, Social Security numbers) as well as data linked to **27 pharmaceutical and biotechnology partners**. The breach led to a **class-action lawsuit**, with Cencora agreeing to compensate affected individuals up to **$5,000 per person**, capped at **$5 million total** for documented losses. The incident exposed critical internal and partner-related data, posing significant **financial, reputational, and operational risks** to the company and its stakeholders.


No incidents recorded for Cencora in 2025.
No incidents recorded for Cencora in 2025.
No incidents recorded for Cencora in 2025.
Cencora cyber incidents detection timeline including parent company and subsidiaries

Cencora, a company building on the legacy of AmerisourceBergen, is a leading global pharmaceutical solutions organization centered on improving the lives of people and animals around the world. We connect manufacturers, providers, and patients to ensure that anyone can get the therapies they need, where and when they need them. We also help our partners bring their innovations to patients more efficiently to accelerate positive outcomes. Becoming Cencora has allowed us to combine all the companies and services of AmerisourceBergen. Now, as a unified and internationally inclusive brand, we’re continuing to invest in and focus on our core pharmaceutical distribution business, while also growing our platform of pharma and biopharma services to support pharmaceutical innovation and access. Our 51,000 worldwide team members are shaping the future of healthcare through the power of our purpose: We are united in our responsibility to create healthier futures. AmerisourceBergen, now Cencora, is ranked #10 on the Fortune 500 and #24 on the Global Fortune 500 with more than $290 billion in annual revenue.


BayCare is a leading not-for-profit academic health care system that connects individuals and families to a wide range of services at 16 hospitals, including a children’s hospital, and hundreds of other convenient locations throughout the Tampa Bay and central Florida regions. The system is West Cen

HSS is the world’s leading academic medical center focused on musculoskeletal health. At its core is Hospital for Special Surgery, nationally ranked No. 1 in orthopedics (for the 16th consecutive year), No. 3 in rheumatology by U.S. News & World Report (2025-2026), and the best pediatric orthopedic

Allegheny Health Network is an integrated health care delivery system serving the greater Western Pennsylvania region. More than 2,600 physicians and 21,000 employees serve the system's 14 hospitals as well as its ambulatory medical and surgery centers, Health + Wellness Pavilions, and hundreds of p

At Johnson & Johnson MedTech, we are working to solve the world’s most pressing healthcare challenges through innovations at the intersection of biology and technology. With deep expertise in surgery, orthopaedics, cardiovascular, and vision, we design healthcare solutions that are smarter, less inv
DaVita means “to give life,” reflecting our proud history as leaders in dialysis—an essential, life-sustaining treatment for those living with end stage kidney disease (ESKD). Today, our mission is to minimize the devastating impacts of kidney disease across the full spectrum of kidney health care.

Beth Israel Deaconess Medical Center (BIDMC) is part of Beth Israel Lahey Health, a new health care system that brings together academic medical centers and teaching hospitals, community and specialty hospitals, more than 4,000 physicians and 35,000 employees in a shared mission to expand access to

NHG Health is a leading public healthcare provider in Singapore recognised for its quality clinical care and its commitment in enabling healthier lives through preventive health, innovative solutions and person-centred programmes tailored to every life stage. Our integrated health system, which span

Be at the heart of exceptional care. Team MHS Florida is an award-winning group of friends and colleagues at one of the largest not-for-profit health systems in the nation. We're 17,000 strong, advancing towards a brighter future together. We're passionate about the work we do, delivering deep, pe

After the acquisition of the Capio Group in 2018, Ramsay Santé has become Europe's leading private hospital and primary care companies. The group now has 36,000 employees and works with nearly 8,600 private practitioners. Present in 5 countries, France, Sweden, Norway, Denmark and Italy, the group
.png)
A US pharmaceutical giant has agreed to compensate those who were impacted by a major 2024 data breach. According to the newly updated...
Cencora, The Lash Group, and their affiliates have agreed to pay $40 million to settle class action data breach litigation over a February...
Cencora, Inc. has recently notified affected individuals that their personal and sensitive medical details were stolen in a cyberattack.
Most CISOs plan to enhance their crisis simulation capabilities in 2025 to better prepare for potential full-scale cyber crises, according to a new study by...
Questions remain about how a public company can pay $75 million to the Dark Angels ransomware gang without any disclosures to shareholders...
Here are our favorite cybersecurity stories of this year written by our friends at rival outlets.
Some of the largest, most damaging breaches of 2024 already account for over a billion stolen records. Plus, some special shout-outs.
Cencora faced criticism after paying a ransom of Rp1.15 trillion in bitcoin due to cyber attacks (Photo; Doc. Techcrunch).
Cencora paid $75 million ransom following a cyberattack, marking the largest extortion payment ever, with the breach involving sensitive...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Cencora is https://www.cencora.com/.
According to Rankiteo, Cencora’s AI-generated cybersecurity score is 788, reflecting their Fair security posture.
According to Rankiteo, Cencora currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Cencora is not certified under SOC 2 Type 1.
According to Rankiteo, Cencora does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Cencora is not listed as GDPR compliant.
According to Rankiteo, Cencora does not currently maintain PCI DSS compliance.
According to Rankiteo, Cencora is not compliant with HIPAA regulations.
According to Rankiteo,Cencora is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Cencora operates primarily in the Hospitals and Health Care industry.
Cencora employs approximately 25,517 people worldwide.
Cencora presently has no subsidiaries across any sectors.
Cencora’s official LinkedIn profile has approximately 192,720 followers.
Cencora is classified under the NAICS code 62, which corresponds to Health Care and Social Assistance.
No, Cencora does not have a profile on Crunchbase.
Yes, Cencora maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/cencoraglobal.
As of December 11, 2025, Rankiteo reports that Cencora has experienced 1 cybersecurity incidents.
Cencora has an estimated 30,928 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Breach.
Detection and Response: The company detects and responds to cybersecurity incidents through an communication strategy with data breach notification letters (e.g., dated 2024-12-12), communication strategy with settlement portal for claims..
Title: Cencora (formerly AmerisourceBergen) Data Breach (2024)
Description: A major data breach at Cencora (COR) in 2024 exposed personal information of over 1.4 million individuals, including employees and partners from 27+ pharmaceutical and biotechnology companies. The breach involved exfiltration of sensitive data such as names, addresses, dates of birth, and Social Security numbers. A class-action lawsuit followed, leading to a settlement offering up to $5,000 per affected individual (capped at $5M total).
Date Publicly Disclosed: 2024-02-01
Type: data breach
Common Attack Types: The most common types of attacks the company has faced is Breach.

Data Compromised: Personal information (names, addresses, dob, ssn), Sensitive private information
Systems Affected: World Courier Group systemssubsidiaries of Cencora
Brand Reputation Impact: High (class-action lawsuit, public disclosure of 1.4M+ affected individuals)
Legal Liabilities: class-action lawsuitsettlement payments up to $5M
Identity Theft Risk: High (SSN and PII exposed)
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Personally Identifiable Information (Pii), Employee Records, Partner Company Data and .

Entity Name: Cencora (COR)
Entity Type: public company
Industry: pharmaceutical distribution
Location: Pennsylvania, USA
Size: 51,000 employees, $290B annual revenue
Customers Affected: 1,400,000+ individuals (including employees and partners)

Entity Name: World Courier Group
Entity Type: subsidiary
Industry: logistics/pharmaceutical supply chain

Entity Name: 27+ partner pharmaceutical and biotechnology companies
Entity Type: business partners
Industry: pharmaceutical, biotechnology

Communication Strategy: data breach notification letters (e.g., dated 2024-12-12)settlement portal for claims

Type of Data Compromised: Personally identifiable information (pii), Employee records, Partner company data
Number of Records Exposed: 1,400,000+
Sensitivity of Data: High (includes SSN, DOB, addresses)
Personally Identifiable Information: namesaddressesdates of birthSocial Security numbers

Data Exfiltration: True

Legal Actions: class-action lawsuit, settlement agreement,
Ensuring Regulatory Compliance: The company ensures compliance with regulatory requirements through class-action lawsuit, settlement agreement, .

Source: The Daily Hodl

Source: Cencora Data Breach Settlement Portal

Source: Cencora Data Breach Notification Letter (2024-12-12)
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: The Daily Hodl, and Source: Cencora Data Breach Settlement Portal, and Source: Cencora Data Breach Notification Letter (2024-12-12).
Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Data Breach Notification Letters (E.G., Dated 2024-12-12) and Settlement Portal For Claims.

Customer Advisories: settlement claims process for affected individuals
Advisories Provided: The company provides the following advisories to stakeholders and customers following an incident: were Settlement Claims Process For Affected Individuals and .

High Value Targets: Employee Pii, Partner Company Data,
Data Sold on Dark Web: Employee Pii, Partner Company Data,
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2024-02-01.
Most Significant Data Compromised: The most significant data compromised in an incident were personal information (names, addresses, DOB, SSN), sensitive private information and .
Most Significant System Affected: The most significant system affected in an incident was World Courier Group systemssubsidiaries of Cencora.
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were sensitive private information, personal information (names, addresses, DOB and SSN).
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 1.4M.
Most Significant Legal Action: The most significant legal action taken for a regulatory violation was class-action lawsuit, settlement agreement, .
Most Recent Source: The most recent source of information about an incident are Cencora Data Breach Settlement Portal, The Daily Hodl and Cencora Data Breach Notification Letter (2024-12-12).
Most Recent Customer Advisory: The most recent customer advisory issued was an settlement claims process for affected individuals.
.png)
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through 17.0.9 have a weak default password. By default, this is a 6 digit numeric value which can be brute forced. (This is the app_password parameter). Depending on local configuration, this password could be the extension, voicemail, user manager, DPMA or EPM phone admin password. This issue is fixed in versions 16.0.96 and 17.0.10.
Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool executes arbitrary SQL provided by the caller using PDO::prepare() + execute() without semantic restrictions. This is consistent with the name (“write tool”), but in an LLM/agent context it becomes a high-risk capability: prompt injection or indirect prompt manipulation can cause execution of destructive queries such as DROP TABLE, TRUNCATE, DELETE, ALTER, or privilege-related statements (subject to DB permissions). Deployments that expose an agent with MySQLWriteTool enabled to untrusted input and/or run the tool with a DB user that has broad privileges are impacted. This issue is fixed in version 2.8.12.
Neuron is a PHP framework for creating and orchestrating AI Agents. Versions 2.8.11 and below use MySQLSelectTool, which is vulnerable to Read-Only Bypass. MySQLSelectTool is intended to be a read-only SQL tool (e.g., for LLM agent querying, however, validation based on the first keyword (e.g., SELECT) and a forbidden-keyword list does not block file-writing constructs such as INTO OUTFILE / INTO DUMPFILE. As a result, an attacker who can influence the tool input (e.g., via prompt injection through a public agent endpoint) may write arbitrary files to the DB server if the MySQL/MariaDB account has the FILE privilege and server configuration permits writes to a useful location (e.g., a web-accessible directory). This issue is fixed in version 2.8.12.
Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may arise from concurrent requests using the ApiClient class. This could cause a status code or response header from one request’s response to influence another request’s response. This issue is fixed in version 20.0.1.
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache for the request results. This issue is fixed in versions 4.11.2 and 4.12.1.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.
