Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
AmerisourceBergen

AmerisourceBergen Vendor Cyber Rating & Cyber Score

amerisourcebergen.com

On August 30, 2023, AmerisourceBergen became Cencora. Cencora is a leading global pharmaceutical solutions organization centered on improving the lives of people and animals around the world. We partner with pharmaceutical innovators across the value chain to facilitate and optimize market access to therapies. Care providers depend on us for the secure, reliable delivery of pharmaceuticals, healthcare products, and solutions. Previously known as AmerisourceBergen, our new name, Cencora, unites our 46,000+ team members under one identity in pursuit of a shared purpose: We are united in our responsibility to create healthier futures. : We are united in our responsibility to create healthier futures. AmerisourceBergen is ranked #11 on the


AmerisourceBergen A.I CyberSecurity Scoring

AmerisourceBergen
Company Information
Website:http://www.amerisourcebergen.com
Employees number:6,552
Number of followers:133,856
NAICS:62
Industry Type:Hospitals and Health Care
Homepage:amerisourcebergen.com
AmerisourceBergen Risk Score (AI oriented)
Between 0 and 549
logo
AmerisourceBergenHospitals and Health Care
Updated:
31/03/2026
525/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
AmerisourceBergen Global Score (TPRM)
xxxx
logo
AmerisourceBergenHospitals and Health Care
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

AmerisourceBergen
AmerisourceBergenCritical
Current Score
525C (CRITICAL)
01000
5 incidents
-102 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
537Before Incident
MAY 2026
533Before Incident
APRIL 2026
530Before Incident
MARCH 2026
525Before Incident
FEBRUARY 2026
520Before Incident
JANUARY 2026
516Before Incident
DECEMBER 2025
507Before Incident
NOVEMBER 2025
506Before Incident
OCTOBER 2025
500Before Incident
SEPTEMBER 2025
595Before Incident
Breach
19 Sep 2025AmerisourceBergen
Cencora Inc.

Cencora Inc. and The Lash Group LLC Data Breach

493After Incident
CRITICAL-102
AME4762047092025
Cencora Inc. (formerly AmerisourceBergen) and its subsidiary, The Lash Group, faced a massive data breach compromising personal and protected health information (PHI) of individuals across the U.S. and its territories. The incident led to a $40 million class-action settlement, with allegations that the company failed to implement adequate cybersecurity measures, exposing sensitive data to unauthorized access. Affected individuals—those notified directly or via suspicious activity linked to the breach—could claim up to $5,000 for documented losses (e.g., fraud, identity theft) or a pro-rata cash payment. The breach’s fallout included financial fraud risks, reputational damage, and potential long-term harm to victims, with California residents eligible for double compensation under state laws. The settlement covers administrative costs, legal fees, and payouts, with final approval pending in early 2026. Cencora denied liability but settled to avoid prolonged litigation, highlighting the severe operational and legal consequences of the data exposure.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Financial Loss: $40,000,000 (settlement fund)Personal informationProtected health information (PHI)Customer Complaints: Class action lawsuit filed by affected individualsBrand Reputation Impact: Significant (class action settlement and public disclosure)Legal Liabilities: $40,000,000 settlement, attorneys' fees ($13,333,333.33), and other legal costsIdentity Theft Risk: High (unauthorized use of personal information reported)
DATA BREACH
Personal informationProtected health information (PHI)Sensitivity Of Data: High (includes health and personally identifiable information)Data Exfiltration: Yes (alleged unauthorized use of personal information)Personally Identifiable Information: Yes
AUGUST 2025
593Before Incident
JULY 2025
590Before Incident
AUGUST 2024
597Before Incident
Breach
14 Aug 2024AmerisourceBergen
AmerisourceBergen Specialty Group, LLC

Data Breach at AmerisourceBergen Specialty Group, LLC

544After Incident
CRITICAL-53
AME345072925
The Vermont Office of the Attorney General reported a data breach involving AmerisourceBergen Specialty Group, LLC on October 8, 2024. The breach was confirmed to have affected personal information, including names, addresses, dates of birth, health insurance information, and medical record numbers, with no evidence of fraudulent use reported. The breach occurred on August 14, 2024, when the data was exfiltrated from ABSG's information systems.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
namesaddressesdates of birthhealth insurance informationmedical record numbers
DATA BREACH
namesaddressesdates of birthhealth insurance informationmedical record numbersSensitivity Of Data: High
APRIL 2024
634Before Incident
Breach
03 Apr 2024AmerisourceBergen
AmerisourceBergen Specialty Group, LLC

Data Breach at AmerisourceBergen Specialty Group, LLC

582After Incident
CRITICAL-52
AME425072825
On May 31, 2024, the Vermont Office of the Attorney General reported a data breach involving AmerisourceBergen Specialty Group, LLC (ABSG). The breach was confirmed on April 3, 2024, and involved the exfiltration of personal information, including names, health information, and Medicare/Medicaid numbers, although the number of affected individuals is unknown.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
nameshealth informationMedicare/Medicaid numbers
DATA BREACH
nameshealth informationMedicare/Medicaid numbersSensitivity Of Data: High
FEBRUARY 2024
731Before Incident
Breach
01 Feb 2024AmerisourceBergen
Cencora (formerly AmerisourceBergen)

Cencora Data Security Incident

629After Incident
CRITICAL-102
AME4532245093025
In February 2024, Cencora—a Fortune 10 pharmaceutical distributor—and its subsidiary The Lash Group disclosed a massive data breach affecting over 1.4 million U.S. individuals. The incident exposed highly sensitive personal and health data, including names, addresses, Social Security numbers, dates of birth, health/insurance records, political opinions, criminal history, fingerprint data, and driver’s license/passport details. The breach impacted over 30 pharmaceutical clients, with notifications sent to state attorneys general confirming the scale. A $40 million class-action settlement was approved in July 2024, offering victims up to $5,000 for documented losses tied to identity theft, fraud, or credit monitoring. Cencora denied liability but agreed to the payout, with claims processed by Kroll Settlement Administration. The breach’s severity stems from the comprehensive exposure of personally identifiable information (PII) and protected health information (PHI), posing long-term risks of fraud, financial harm, and reputational damage to affected individuals.
INCIDENT DETAILS -
TYPE
Data BreachClass Action Lawsuit
IMPACT
Financial Loss: $40 million (settlement fund)NamesAddressesDates of birthSocial Security numbersHealth and insurance informationPolitical opinionsCriminal historyFingerprint informationDriver's license informationPassport informationCustomer Complaints: Class action lawsuit filed (Anaya, et al. v. Cencora, Inc.)Brand Reputation Impact: Significant (settlement and public disclosure)Legal Liabilities: $40 million settlement (pending final approval)Identity Theft Risk: High (sensitive PII exposed)
DATA BREACH
Personally Identifiable Information (PII)Protected Health Information (PHI)Biometric DataGovernment-Issued IDsNumber Of Records Exposed: 1.4+ million (estimated)Sensitivity Of Data: High (includes SSNs, health data, biometrics)Data Exfiltration: YesPersonally Identifiable Information: Yes (comprehensive PII)
FEBRUARY 2023
779Before Incident
Breach
01 Feb 2023AmerisourceBergen
AmerisourceBergen

AmerisourceBergen Data Breach

720After Incident
MEDIUM-59
AME62016223
Pharmaceutical distributor AmerisourceBergen suffered from a data breach incident in that hackers compromised the IT system of one of its subsidiaries after threat actors began leaking allegedly stolen data. All files are purportedly taken from AmerisourceBergen and MWI Animal Health, most likely the subsidiary that was compromised has been shared by the Lorenz ransomware organization. They promptly enlisted the necessary teams to contain the disruption, limit the infiltration, and take precautions to make sure all systems were free of any intrusions—which they are currently.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
All files are purportedly taken from AmerisourceBergen and MWI Animal HealthIT system of one of its subsidiaries
DATA BREACH
All files are purportedly taken from AmerisourceBergen and MWI Animal Health

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for AmerisourceBergen ?
?
What was AmerisourceBergen's A.I Rankiteo Cyber Score in May 2026 ?
?
What was AmerisourceBergen's A.I Rankiteo Cyber Score in April 2026 ?
?
What was AmerisourceBergen's A.I Rankiteo Cyber Score in March 2026 ?
?
What was AmerisourceBergen's A.I Rankiteo Cyber Score in February 2026 ?
?
What was AmerisourceBergen's A.I Rankiteo Cyber Score in January 2026 ?
?
What was AmerisourceBergen's A.I Rankiteo Cyber Score in December 2025 ?
?
What was AmerisourceBergen's A.I Rankiteo Cyber Score in November 2025 ?
?
What was AmerisourceBergen's A.I Rankiteo Cyber Score in October 2025 ?
?
What was AmerisourceBergen's A.I Rankiteo Cyber Score in September 2025 ?
?
What was AmerisourceBergen's A.I Rankiteo Cyber Score in August 2025 ?
?
What was AmerisourceBergen's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on AmerisourceBergen's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with AmerisourceBergen ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view AmerisourceBergen's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?