us

216.73.217.135

Back
News

Ransomware Attack Exposes 5.8 Million Pharmaceutical Records of PharMerica Corporation

Ransomware Attack Exposes 5.8 Million Pharmaceutical Records of PharMerica Corporation
R Richard M. MAY 16, 2023 1 minute read

A breach notification was filed with the Maine Attorney General’s Office for the first time, revealing data theft. The breach was discovered on March 21st, however, had taken place 11 days prior, on March 12th. During a ransomware attack last week, 5.8 million patient records from PharMerica Corp. were stolen and published online.

The first indication of data theft was provided in a breach notice filed with the Maine Attorney General’s Office. This breach was discovered on March 21st after occurring on March 12th. PharmaMerica Corp., a Fortune 1000 company and pharmacy services provider, has been attacked by ransomware. This has resulted in the theft and publication of healthcare data from 5.8 million patients. Even though the company did not disclose the exact nature of the attack, it is described as an “external system breach (hacking)” in the breach notification.

PharMerica has stated the data breach occurred on March 12th, contrary to the breach notice, which indicates a discovery date of March 21st. Personal details, including names, addresses, date of birth, social security numbers, medications, and health insurance details, were stolen.

According to the breach notification letter, there has been no evidence of fraud or identity theft using personal information. However, that may not have been the best of intentions, given that the ransomware group responsible for the attack has already made the stolen information public.

As reported today by Bleeping Computer, the ransomware gang Money Message took responsibility for the attack on March 12th. According to the group, they breached BrightSpring, a healthcare provider that merged with PharMerica in 2019. The hacker group abandoned all stolen records on a hacking website after failing to secure a ransom payment by April 9th, the deadline for payment.

A new ransomware gang known as Money Message has been detected since March. After claiming responsibility for the attack, this group attacked Taiwanese hardware manufacturer Micro-Star International Co Ltd in April.

“This is a devastating data breach both in terms of size and the severity of what was leaked,” said Comparitech consumer privacy advocate Paul Bischoff. “ Social Security and health insurance information poses the most immediate threat. They could be used for identity theft and medical benefits fraud.”

He explained that identity thieves might attempt to obtain credit in the name of the deceased, “who obviously aren’t going to check their credit reports. That puts the onus of responsibility on relatives, who could be on the hook for the deceased’s debts. I suspect this attack disproportionately affects the elderly as well, who are frequently targeted by fraud.”

Suggested Read:

THE NAIVAS DATA BREACH | A WAKE-UP CALL FOR FIRMS TO FOLLOW PRIVACY LAWS

Disclaimer: The views and opinions expressed on this webpage or weblink are those of the author only, and are not necessarily the views or opinions of Shufti Pro Limited. The material and information on this weblink is solely for general information purposes. You should not rely upon the material or information on the website as a basis for making any business or legal decision.

While we endeavor to keep the information up-to-date and/or correct, we make no representations or warranties of any kind, express or implied, or for any purpose about the completeness, accuracy, reliability, suitability, or availability of the contents or information herein. Any reliance on its content is thus entirely at your own risk.

For the avoidance of doubt, Shufti Pro Limited will not be liable for any false, inaccurate, inappropriate, or incomplete information presented herein, and all liabilities with respect to actions taken, or not taken, based on the contents or information herein, or for any loss sustained by you as a consequence are hereby expressly disclaimed by us.

Share you link

Bring your voice

Bring Your Voice.

The community for every hand that writes and every voice that speaks against fraud.

Join Community

Pitch a piece and get a verified byline in the Media room.

“Industry Partnerships That Create Real Value”

Join Shufti’s partnership network to expand your connections, collaborate with industry leaders, and unlock new opportunities.

Pitch a piece and get a verified byline in the Media room.

Partnership Inquiries?
Email us at [email protected]

iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild ISO 27001:2022 KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
Copyright © 2026 Shufti. All rights reserved.