AmerisourceBergen/Censora - MWI Animal Health Listed by lorenz Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The AmerisourceBergen/Censora - MWI Animal Health Listed by lorenz Ransomware Group (reported February 6, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
In early February 2023, a listing appeared on a ransomware leak site that named AmerisourceBergen in connection with its MWI Animal Health business, also referenced as Censora. The listing asserted that internal files had been taken. For employees, partners, veterinary clients, and others whose information might sit inside corporate systems, the practical question is straightforward: what, if anything, left the organisation’s control, and what risk does that create in daily life.
Public detail remains limited. The number of people affected is unknown, and the precise contents of any stolen material have not been independently confirmed. What is known is the claim itself and the date it was reported. That is enough to warrant careful attention, but not enough to assume the worst.
Inside the incident
On or around 6 February 2023, AmerisourceBergen, under the related names Censora and MWI Animal Health, was listed on the leak site operated by the lorenz ransomware group. According to the group’s own statement on that site, internal data had been exfiltrated in a ransomware attack. No further technical description of the intrusion method, the duration of any access, or the volume of material involved has been made public in the available record.
The scale of the incident is undisclosed. No confirmed figure for affected individuals or organisations has been released. The facts state only that internal files were claimed to have been stolen. Whether any ransom demand was paid, whether negotiations occurred, or whether data was later published in full is not established in the reported information. The listing itself stands as an unverified claim by the threat actor.
Who is lorenz?
Lorenz is a ransomware operation that has been active for several years and is known for double-extortion tactics. In this model, operators encrypt systems and simultaneously copy data, then threaten to publish the stolen material on a dedicated leak site if payment is not made. The group has previously listed a range of corporate and institutional victims across multiple sectors, using the public exposure of sample files or full archives as leverage.
Like other groups of this type, lorenz typically gains initial access through common vectors such as compromised credentials, phishing, or unpatched remote services, though the specific entry point in any given case is rarely confirmed by the victim. Once inside, the operators move laterally, identify valuable file shares and databases, exfiltrate data, and deploy encryption. The leak-site listing for AmerisourceBergen/Censora – MWI Animal Health follows this established pattern: the group claims to possess internal data and uses the listing to apply pressure. No independent verification of the volume or sensitivity of that data has been supplied in the public facts.
AmerisourceBergen and its sector
AmerisourceBergen is a major pharmaceutical and healthcare distribution company. Through businesses such as MWI Animal Health, it supplies medicines, vaccines, and related products to veterinary practices, clinics, and animal-health providers. Organisations of this kind sit at the centre of complex supply chains. They routinely hold procurement records, customer and clinic account details, inventory and pricing data, employee information, and operational documents that keep distribution running.
A breach affecting a distributor in this sector carries weight beyond a single corporate network. Disruptions or data exposure can affect veterinary practices that rely on timely supply, the confidentiality of business relationships, and the personal information of staff and contacts. Even when clinical patient records are not the primary target, the surrounding commercial and administrative data can still be useful to criminals for fraud, social engineering, or competitive misuse. The consequential nature of the incident therefore stems from the organisation’s role in the animal-health supply chain and the breadth of internal information such firms typically maintain.
The information in question
The available facts state that internal files were exfiltrated in a ransomware attack. No itemised list of data types—such as specific categories of personal identifiers, financial records, or clinical information—has been disclosed. Exact contents remain unconfirmed.
Organisations engaged in pharmaceutical and animal-health distribution commonly store a mix of business and personal data: employee records, customer and clinic account information, contracts, shipping and invoicing details, internal correspondence, and operational documents. Whether any of those categories were among the files claimed by lorenz is not established. Readers should treat assertions about precise data elements as unverified until corroborated by the organisation or by independent evidence.
The real-world impact
For individuals, the concrete risks depend on what was actually taken. If employee or contact data were included, possible outcomes include targeted phishing, identity-driven fraud, or unwanted contact. If commercial files were involved, business partners could face competitive exposure or follow-on social-engineering attempts that reference real invoices or relationships. Because the number of people affected is unknown and the data types are not itemised, these remain potential rather than proven harms.
For the organisation, a ransomware listing creates operational, legal, and reputational pressure. Systems may have been encrypted or taken offline; investigation and recovery consume resources; and regulators or contractual partners may require notification once the scope is clearer. None of these consequences has been detailed in the public facts, so their extent is unconfirmed. The lasting impact hinges on whether the claimed data is released, how sensitive it proves to be, and how quickly affected parties can reduce misuse.
Were you affected?
If you have a past or present relationship with AmerisourceBergen, MWI Animal Health, or related entities—as an employee, contractor, clinic customer, or supplier—consider practical steps while public detail remains thin:
- Treat unsolicited messages that reference the company, invoices, or account details with caution; verify through known official channels before responding or clicking links.
- Monitor financial and account statements for unfamiliar activity and enable stronger authentication where available.
- Review any breach notifications you receive directly from the organisation and follow the specific guidance they provide.
- Preserve evidence of suspicious contacts and report clear fraud attempts to the relevant authorities.
You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. That check does not confirm or rule out involvement in this specific incident, but it can indicate whether your credentials or personal details appear elsewhere and need attention. Stay alert to official updates from AmerisourceBergen rather than relying solely on threat-actor claims.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Joy Cone Co, Joy Baking group, BoDeans Baking, Altesa Listed by lorenz Ransomware GroupBroad River Retail/Ashley Store Listed by lorenz Ransomware GroupTarolli, Sundheim, Covell & Tummino LLP Listed by lorenz Ransomware GroupHopsteiner Listed by lorenz Ransomware GroupLatest breaches
Publicly posted by lorenz — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.