United States
USA
American Associated Pharmacies detected suspicious activity consistent with a cybersecurity incident on 23 October 2024; subsequent regulatory reporting identifies 13 October as the breach date. During the response, AAP reset credentials and its API Warehouse ordering capability was reduced, with the company later reporting that only limited ordering capabilities had been restored. Embargo claimed ransomware, encryption and data theft, but AAP did not publicly confirm the ransomware attribution, so the mechanism is not classified as ransomware here.
Estimated severity
70 / 100
Source reliability
85 / 100
Approximate Date
13/10/2024
Targeted Company
AMERICAN ASSOCIATED PHARMACIES
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
No information
United States
USA
No other affected countries reported
Target country
United States
Affected countries
Impacted regions
No information
Duration
No information
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
Attack types
No information
Attributed threat actors
Please rotate your phone