Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Cencora

Cencora Vendor Cyber Rating & Cyber Score

cencora.com

Cencora, a company building on the legacy of AmerisourceBergen, is a leading global pharmaceutical solutions organization centered on improving the lives of people and animals around the world. We connect manufacturers, providers, and patients to ensure that anyone can get the therapies they need, where and when they need them. We also help our partners bring their innovations to patients more efficiently to accelerate positive outcomes. Becoming Cencora has allowed us to combine all the companies and services of AmerisourceBergen. Now, as a unified and internationally inclusive brand, we’re continuing to invest in and focus on our core pharmaceutical distribution business, while also growing our platform of pharma and biopharma services


Cencora A.I CyberSecurity Scoring

Cencora
Company Information
Website:https://www.cencora.com/
Employees number:27,718
Number of followers:201,207
NAICS:62
Industry Type:Hospitals and Health Care
Homepage:cencora.com
Cencora Risk Score (AI oriented)
Between 700 and 749
logo
CencoraHospitals and Health Care
Updated:
07/05/2026
744/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Cencora Global Score (TPRM)
xxxx
logo
CencoraHospitals and Health Care
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Cencora
CencoraModerate
Current Score
744Ba (MODERATE)
01000
2 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
749Before Incident
MAY 2026
745Before Incident
APRIL 2026
751Before Incident
MARCH 2026
749Before Incident
FEBRUARY 2026
748Before Incident
JANUARY 2026
748Before Incident
DECEMBER 2025
747Before Incident
NOVEMBER 2025
746Before Incident
OCTOBER 2025
744Before Incident
SEPTEMBER 2025
743Before Incident
AUGUST 2025
741Before Incident
JULY 2025
740Before Incident
JANUARY 2025
780Before Incident
Breach
01 Jan 2025Cencora
Cencora and Inotiv: Hidden Liability: Why Legacy Web Forms Put Life Sciences Organizations at Critical Risk

Pharmaceutical Sector’s Outdated Web Forms Expose Critical Cybersecurity Risks

729After Incident
CRITICAL-51
INOCEN1775802306
Pharmaceutical Sector’s Outdated Web Forms Expose Critical Cybersecurity Risks The pharmaceutical and life sciences industry, despite heavy investment in advanced R&D and manufacturing, remains vulnerable due to reliance on outdated web forms lacking modern security protocols. These legacy systems used for clinical trial recruitment, adverse event reporting, and regulatory submissions create significant risks, including data breaches, regulatory penalties, and operational disruptions that undermine research integrity and intellectual property protection. Between January and September 2025, an analysis of 172 recorded incidents revealed that 29.1% of attacks on pharmaceutical firms involved ransomware, while 26.7% were data breaches. The average cost of a pharmaceutical data breach reached $5.1 million per incident exceeding the global average of $4.44 million. Regulatory fines have also intensified, with one-third of breached organizations facing penalties, and the share of fines exceeding $100,000 rising 19.5% year-over-year. ### Compliance Failures and Security Gaps Legacy web forms often fail to meet critical regulatory standards, including FDA 21 CFR Part 11, GDPR, and GxP requirements. Key deficiencies include: - Lack of tamper-proof audit trails, violating ALCOA+ principles for data integrity. - Unencrypted data transmission, exposing sensitive information to interception. - Weak authentication, leaving systems vulnerable to SQL injection, cross-site scripting (XSS), and session hijacking. GDPR violations carry severe penalties, with fines reaching €20 million or 4% of global revenue, while data sovereignty breaches can result in operational bans in entire countries. ### High-Profile Breaches Highlight Industry Vulnerabilities Recent incidents underscore the operational and financial impact of these weaknesses: - Inotiv (2025): A ransomware attack encrypted systems, disrupted operations, and compromised 170 GB of sensitive data. - AEP (Germany, 2025): Partial IT encryption threatened medicine deliveries to 6,000 pharmacies. - Cencora (2024): A breach exposed data from 27 pharmaceutical and biotech firms, leading to a $40 million settlement in 2025. ### Third-Party Risks Amplify Exposure Pharmaceutical companies relying on third-party platforms face additional vulnerabilities. 87% of firms report being affected by breaches in their vendor ecosystems, with third-party breaches now accounting for 30% of incidents double the 2024 rate. Clinical trial data, worth hundreds of millions, is particularly at risk when legacy forms lack data localization controls or GDPR-compliant transfer safeguards. ### The Cost of Inaction Organizations spend 60-80% of IT budgets maintaining legacy systems, diverting resources from modernization. Yet, the financial toll of breaches persists long-term: 58% of breach costs accumulate after the first year, extending regulatory scrutiny and reputational damage. Regulatory guidance is clear systems without audit trails, encryption, and role-based access controls must be replaced. As cyber threats evolve, pharmaceutical firms can no longer treat web forms as low-priority infrastructure. The urgency to modernize is not just a compliance issue but a critical defense against escalating cyber risks.
INCIDENT DETAILS -
TYPE
ransomwaredata breach
IMPACT
Financial Loss: $5.1 million per incident (average data breach cost)170 GB of sensitive data (Inotiv)clinical trial dataadverse event reportsregulatory submission datalegacy web formsIT systems (partial encryption in AEP case)third-party vendor platformsDowntime: Disrupted operations (Inotiv), threatened medicine deliveries to 6,000 pharmacies (AEP)disrupted research integrityoperational disruptionsmedicine delivery threatsBrand Reputation Impact: Reputational damage, long-term scrutiny$40 million settlement (Cencora)regulatory fines exceeding $100,000
DATA BREACH
clinical trial dataadverse event reportsregulatory submission datapersonally identifiable informationSensitivity Of Data: high (worth hundreds of millions)Data Exfiltration: 170 GB (Inotiv)Data Encryption: partial IT encryption (AEP)Personally Identifiable Information: yes
FEBRUARY 2024
826Before Incident
Breach
01 Feb 2024Cencora
Cencora (COR)

Cencora (formerly AmerisourceBergen) Data Breach (2024)

773After Incident
CRITICAL-53
CEN2702127093025
In February 2024, Cencora, a US pharmaceutical giant with over $290 billion in annual revenue and 51,000 employees, suffered a major data breach targeting its subsidiary, World Courier Group. Hackers infiltrated the company’s systems and exfiltrated sensitive personal information of over 1.4 million individuals, including current and former employees (names, addresses, dates of birth, Social Security numbers) as well as data linked to 27 pharmaceutical and biotechnology partners. The breach led to a class-action lawsuit, with Cencora agreeing to compensate affected individuals up to $5,000 per person, capped at $5 million total for documented losses. The incident exposed critical internal and partner-related data, posing significant financial, reputational, and operational risks to the company and its stakeholders.
INCIDENT DETAILS -
TYPE
data breachcybersecurity attack
IMPACT
personal information (names, addresses, DOB, SSN)sensitive private informationWorld Courier Group systemssubsidiaries of CencoraBrand Reputation Impact: High (class-action lawsuit, public disclosure of 1.4M+ affected individuals)class-action lawsuitsettlement payments up to $5MIdentity Theft Risk: High (SSN and PII exposed)
DATA BREACH
personally identifiable information (PII)employee recordspartner company dataNumber Of Records Exposed: 1,400,000+Sensitivity Of Data: High (includes SSN, DOB, addresses)namesaddressesdates of birthSocial Security numbers

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Cencora ?
?
What was Cencora's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Cencora's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Cencora's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Cencora's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Cencora's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Cencora's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Cencora's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Cencora's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Cencora's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Cencora's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Cencora's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Cencora's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Cencora ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Cencora's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?