American Associated Pharmacies (AAP), a member-owned cooperative in the pharmaceutical industry, recently disclosed a cybersecurity incident that may have exposed sensitive personal information. The breach occurred on October 23, 2024, when AAP detected suspicious activity within its systems, consistent with a cyberattack.
The company immediately launched an investigation and worked with cybersecurity experts to contain and remediate the situation.
While the exact number of individuals affected has not been disclosed, the potentially compromised information includes:
The breach was reported to the state attorney general office in Massachusetts, where the disclosure was made on December 27, 2024. At this time, there is no evidence that the stolen data has been used for identity theft or fraud. However, the sensitive nature of the exposed information poses significant risks to affected individuals.
AAP has taken several steps to address the breach and protect the information in its care. Upon discovering the incident, the company immediately shut down its systems to prevent further unauthorized access. It also implemented enhanced security measures, such as expanding the use of multifactor authentication, resetting all passwords, and deploying additional monitoring tools to detect future threats.
To assist affected individuals, AAP is offering 24 months of complimentary credit monitoring and identity protection services through Experian IdentityWorks. The company has also reported the incident to relevant government agencies and continues to work with privacy and security experts to strengthen its systems.
If you believe your information may have been impacted by this data breach, it is essential to take proactive steps to protect yourself. Here’s what you should do: