Desk live·
ForensicPost
Ransomware/Extortion/File 24-0221b

The Largest Ransom on Record, and a Filing That Mentions No Ransom

Cencora told the SEC that data had been exfiltrated and that the incident had not materially affected operations. Analysts separately traced a $75m payment, the largest ever recorded. Both statements can be true at once, and that is the finding.

Constructed geometry · not a chart of case data
JurisdictionUSAConshohocken, Pennsylvaniathe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetCencora
ActorDark Angels
S. Rosler13 min readConfidence: medium5 sources reviewed

On 21 February 2024 the pharmaceutical distributor Cencora, formerly AmerisourceBergen, learned that data had been taken from its systems. It filed a Form 8-K under Item 1.05 six days later. This desk has retrieved that filing from EDGAR and read it.

On February 21, 2024, Cencora, Inc. learned that data from its information systems had been exfiltrated, some of which may contain personal information.

Cencora, Inc., Form 8-K, Item 1.05, filed 27 February 2024

The filing goes on to say that the incident "has not had a material impact on the Company’s operations, and its information systems continue to be operational", and that the company had "not yet determined whether the incident is reasonably likely to materially impact" its financial condition or results.

That is the whole of the disclosure. It runs to two paragraphs, and there is nothing wrong with it.

Five Months Later, A Number Appeared From Somewhere Else

On 29 July 2024 Zscaler’s ThreatLabz reported that a Fortune 50 company had paid $75m to the Dark Angels ransomware operation. Chainalysis subsequently confirmed the figure as the largest ransom payment it had ever recorded, against a previous high of $40m paid by CNA Financial in 2021.

Zscaler did not name the victim and has continued not to. Reporters reasoned towards Cencora from the timing, the sector and the 8-K. Bloomberg Law then reported, citing people it did not name, that Cencora had paid — $150m demanded, $75m settled, three bitcoin transfers in March.

Asked about it, a Cencora representative declined to comment and said the company does not respond to rumour or speculation. As far as this desk can establish, that remains the company’s position.

Sort The Claims By What Is Actually Established

Five assertions, five different evidentiary standardsCencora Form 8-K; Zscaler ThreatLabz; Chainalysis; Bloomberg Law; settlement reporting
TimeEventEvidence
Data exfiltratedCencora’s own SEC filingEstablished — primary document, read by this desk
$75m movedTraced by blockchain analysisEstablished — the payment exists
Payer was Fortune 50Zscaler ThreatLabz reportReported; victim deliberately unnamed
Payer was CencoraBloomberg Law, unnamed sourcesReported only — not confirmed by Cencora
1.43m people, $40m settlementNotifications and court filingsEstablished

The desk grades this file medium for one reason: the largest and most quoted number in it is the one whose owner is least established. A $75m payment to Dark Angels happened. That Cencora made it is a reported attribution resting on unnamed sources and on an inference from timing.

The Filing And The Payment Do Not Contradict Each Other

It is tempting to read the 8-K as evasive — a company saying nothing much happened while, on the reported account, wiring the largest extortion payment in history. That reading is wrong, and the reason it is wrong matters more than the incident.

Item 1.05 asks a registrant to describe the material aspects of a cybersecurity incident’s nature, scope and timing, and its material impact on the registrant. It does not ask whether a ransom was demanded. It does not ask whether one was paid, or how much, or to whom.

So a company can file a complete and accurate disclosure that satisfies the rule and never mention a payment of any size, because the payment is not among the things the rule asks about. Nothing was withheld. Nothing was required.

What That Means For Every Figure In This Database

The corpus records ransom amounts sparingly and always with a provenance label, because they almost never come from the payer. They come from chain analysis, from vendor reports, from leak-site boasts, and occasionally from unnamed sources speaking to a reporter.

This file shows why that will not change. The one party that knows the number is under no obligation to state it, and has a straightforward interest in not doing so. Every published total of ransomware payments is therefore built from traces of the transaction rather than from any record of it — which is a reasonable way to count, and not the same thing as counting.

Set against 24-0711, where a $25m payment was chain-traced and attributed to CDK Global without company confirmation, and 24-0301, where Change Healthcare did confirm paying: the confirmation is the exception in this corpus, not the rule.

The Established Numbers Are The Smaller Ones

Cencora ultimately notified more than 1.43 million individuals, and reporting identified data belonging to patients of more than two dozen pharmaceutical and biotechnology companies that used its services. Names, addresses, dates of birth, diagnoses and prescribed medications were among the categories described.

Cencora and The Lash Group later agreed to pay $40m to settle the consolidated class litigation. That figure is in court filings and is not in dispute.

It is worth holding those two amounts next to each other. If the reported ransom is right, the payment made to keep the data quiet was nearly twice the payment later made to the people whose data it was — and only one of the two was ever compelled.

How we reported this

The Form 8-K was retrieved directly from the SEC EDGAR archive and read in full by this desk; quotations from it are verbatim. The $75m payment is traced by blockchain analysis and reported by Zscaler ThreatLabz and Chainalysis, neither of which named the victim. The attribution of that payment to Cencora originates with Bloomberg Law, citing unnamed sources, and with press inference from timing; Cencora has declined to comment and this desk does not treat the attribution as established. The $150m demand and three-instalment structure carry the same qualification. The 1.43 million notification figure and the $40m settlement are established. Graded medium on account of the central attribution. Corrections: corrections@forensicpost.com.

Sources
  1. Cencora, Inc. — Form 8-K, Item 1.05 Material Cybersecurity IncidentsU.S. Securities and Exchange Commission (EDGAR)
  2. The mystery of the $75M ransom payment to Dark AngelsTechTarget
  3. Hackers got record ransom of $75 million for Cencora breachBloomberg Law
  4. Dark Angels ransomware receives record-breaking $75 million ransomBleepingComputer
  5. Cencora and The Lash Group settle data breach litigation for $40 millionHIPAA Journal
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary