Data breach
Cardinal Health
- Records
- 407,080
- Breach date
- 13 November 2024Estimated
- Added
- 13 November 2024
What was exposed
5 types of data
- Email addresses1
- Names1
- Employment1
- Job titles1
- Phone numbers1
About this breach
Cardinal Health, one of the largest pharmaceutical distributors in the United States, appears in a dataset of more than 407,000 records containing detailed employee information that was posted publicly on a well-known hacking forum in November 2024. According to our investigation team, the dataset was added to our index with an estimated breach date of November 13, 2024. Reporting by SC Media indicates the data likely originated in the 2023 MOVEit file-transfer hack, which has been claimed by the Clop ransomware gang, and was republished by a threat actor using the alias "Nam3L3ss" on BreachForums as part of a larger dump covering at least 25 major companies. Separately, the dark web monitoring firm InsecureWeb reported that a different threat actor advertised the alleged sale of a Cardinal Health database in December 2024, a claim we could not independently verify as of September 25, 2026.
November 11, 2024: The Israeli cybersecurity firm Hudson Rock published analysis of employee directories from 25 major organizations, including Cardinal Health, that had surfaced online.
November 12, 2024: A threat actor using the alias "Nam3L3ss" posted at least 25 CSV datasets on BreachForums containing records likely stolen in the 2023 MOVEit hack; SC Media reported the same day that Cardinal Health accounted for 407,437 exposed records.
What Information Was Compromised?
Our analysis found the following data types in this breach: names, email addresses, phone numbers, and job titles.
Additional detail comes from Hudson Rock research reported by SC Media, which described the leaked material as employee directories containing names, email addresses, phone numbers, cost center codes, and in some cases entire organizational structures. According to SC Media, 407,437 Cardinal Health records were exposed, a figure consistent with the scale in our own index.
The reporting describes workplace contact and directory information rather than financial data, Social Security numbers, or government identification.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Even without financial details, employee directory data is valuable to criminals. Hudson Rock researchers warned that this kind of material "could serve as a goldmine for cybercriminals seeking to engage in phishing, identity theft, or even social engineering attacks on a large scale."
Because the data ties names to job titles, employers, email addresses, and phone numbers, it can be used to craft convincing scams. A message that references your actual role or employer is far more believable than a generic phishing email. Attackers may also impersonate colleagues or managers, since the leaked organizational structure shows who reports to whom.
What Should You Do If You Were Affected?
If you worked at Cardinal Health or received its communications around the relevant period, take a few practical steps:
Treat unexpected emails, texts, or calls that reference your job, employer, or colleagues with suspicion, and verify requests through known internal channels before responding.
Never click links or open attachments in unsolicited messages that claim to come from HR, IT, or company leadership.
Use strong, unique passwords and enable two-factor authentication on your important accounts, especially email, since email access lets attackers reset other passwords.
Be cautious about how much workplace information you share publicly, and report any suspected phishing attempt to your employer's security team.
Cardinal Health has not published a notice specifically addressing this leaked dataset as of September 25, 2026, so affected individuals should not expect notification tied to this listing and should act on their own initiative.
