Henry Schein confirms a cybersecurity incident as ALPHV claims the attack

Organization
Henry Schein
Exploit
Ransomware
Industry
Healthcare

Henry Schein, a Fortune 500 distributor of dental and medical supplies with 2022 revenue above 12 billion dollars, said it detected a cybersecurity incident on October 14, 2023 and disclosed it publicly the following day. The company took certain systems offline to contain the intrusion, temporarily disrupting part of its manufacturing and distribution business. It said its Henry Schein One practice management software was not affected.

The ALPHV group, also known as BlackCat, claimed responsibility and said it had stolen 35 terabytes of data, including payroll and shareholder records. The gang later said it re-encrypted Henry Schein systems after negotiations stalled, timing the second round for the point at which the company had almost finished restoring its network.

Henry Schein said it had contained the incident, engaged outside cybersecurity advisers and notified law enforcement. It warned that customer and personal information may have been exposed, offered complimentary credit monitoring and identity theft protection to affected individuals, and told investors it expected a financial impact for the quarter.

More than three weeks after the initial attack the company's website and webshop were still not fully operational. The ALPHV listing for Henry Schein was subsequently removed from the group's leak site, which BleepingComputer noted usually indicates either a payment or a resumption of negotiations. The company did not confirm either.

Updates

  1. Henry Schein told the Maine attorney general in October 2024 that 166,432 people had personal data taken in the 2023 attacks, up from the 29,112 it had reported in November 2023.

Sources