[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fDFhiF0WYipWaOfG44lBgLQBOgWSxxxDU_aJVN0Dl55Y":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":31,"source":32,"isVerified":4,"isSpamList":33,"isSensitive":4,"severity":34,"processingStatus":35,"logoUrl":36,"contentUpdatedAt":16,"hasEnglishDescription":4},"6a671736fced2fc6f373a90d","WIRXPharmacy2025","WIRX Pharmacy 2025 Data Breach","wirx-pharmacy-2025","wirxpharmacy.com",{"name":12,"sector":13,"country":14,"website":10},"WIRX Pharmacy","Healthcare","United States","2025-12-06T00:00:00.000Z","2026-07-27T08:30:46.566Z",20047,[19,20,21,22,23,24,25,26,27,28,29,30],"Personal information","Protected health information","Names","Diagnoses or conditions","Medications","Other treatment information","Social Security numbers","Addresses","Dates of birth","Other identifiers","Financial account information","Claims information","\u003Cp>\u003Cstrong>The WIRX Pharmacy 2025 data breach\u003C\u002Fstrong> was an unauthorized-access event in the network of a specialty pharmacy serving injured workers on December 6–7, 2025. WIRX identified suspicious activity around December 7, secured its systems, and opened an investigation. The review determined that certain data was accessed or acquired without authorization during that two-day period.\u003C\u002Fp>\n\u003Cp>Affected files could contain names together with diagnoses or conditions, medications, and other treatment information; Social Security numbers, addresses, dates of birth, and other identifiers; and financial-account or claims information. Regulatory records report 20,047 people. LeakData uses that figure for pwnCount and totalRecords; no individual records were imported, so importedRecordCount is zero.\u003C\u002Fp>\n\u003Ch2>How Was the WIRX Pharmacy Breach Confirmed?\u003C\u002Fh2>\n\u003Cp>The primary source is WIRX Pharmacy's “Notice of Data Event” on the company's own domain. The organization directly describes discovery of suspicious activity, the December 6–7 access window, the file review's January 23, 2026 finding, the information categories, notification to federal law enforcement, and the assistance line available to individuals.\u003C\u002Fp>\n\u003Cp>The U.S. Department of Health and Human Services breach portal lists the event as a healthcare-data notification. Claim Depot connects the HHS and state attorney-general filings and reports the nationwide total of 20,047 people and the beginning of notifications. The organization notice supports the event and fields, while regulatory records support the population and notification trail.\u003C\u002Fp>\n\u003Ch2>What Happened on December 6–7, 2025?\u003C\u002Fh2>\n\u003Cp>WIRX observed suspicious activity in its network environment around December 7 and secured its systems. It then investigated the nature and scope of the activity. The technical review found that certain data on WIRX systems was accessed or acquired without authorization from December 6 through December 7. The organization conducted a comprehensive data review to identify the people represented in the affected files.\u003C\u002Fp>\n\u003Cp>That work concluded on January 23, 2026 that personal information or protected health information was present. The public notice does not identify the initial access vector, threat actor, malware, ransom demand, or online publication of data. “Accessed or acquired” confirms potential data acquisition, but does not establish that every field was copied for every individual.\u003C\u002Fp>\n\u003Ch2>What Personal and Demographic Information Was Affected?\u003C\u002Fh2>\n\u003Cp>The official notice lists names, Social Security numbers, mailing addresses, dates of birth, and an “other identifier” category. The combination varies by person and file; it should not be assumed that all 20,047 people had every field present. Because WIRX does not explain the other identifier further, LeakData does not convert it into a specific document such as a driver's license, passport, or patient number.\u003C\u002Fp>\n\u003Cp>A combination of name, address, birth date, and SSN may create lasting exposure to fraudulent credit applications, tax-identity misuse, account-takeover attempts, and targeted phishing. Notice recipients should review credit reports, investigate unexpected new accounts or inquiries, and never provide an SSN, password, or one-time code in messages claiming to come from WIRX or a government agency.\u003C\u002Fp>\n\u003Ch2>What Health and Treatment Information Was in Scope?\u003C\u002Fh2>\n\u003Cp>WIRX expressly said the affected files could include diagnoses or conditions, medications, and other treatment information. These are protected-health-information categories and can link a person to a particular illness, prescription, or care relationship. Because the pharmacy serves injured workers, the exposed context could make fraudulent communications about a workplace injury or treatment process more convincing.\u003C\u002Fp>\n\u003Cp>The source does not separately confirm laboratory results, physician names, service dates, prescription numbers, dosages, medical-record numbers, or insurance-policy numbers. LeakData therefore uses only the disclosed diagnosis or condition, medication, and other treatment-information classes. Individuals should inspect health portals and explanation-of-benefits statements for services or claims they do not recognize.\u003C\u002Fp>\n\u003Ch2>What Does Financial-Account or Claims Information Mean?\u003C\u002Fh2>\n\u003Cp>The notice says files could contain “financial account or claims information.” This encompasses financial-account information or information about a healthcare, insurance, or prescription claim, but the public text does not separately confirm an account-number format, bank name, balance, transaction history, payment-card number, expiration date, CVV, or online-banking password.\u003C\u002Fp>\n\u003Cp>LeakData does not add details absent from the source and does not elevate broad labels on a secondary page over the official disclosure. Recipients should report unfamiliar transactions or claims in banking and insurance records directly to the relevant institution. Unsolicited calls about healthcare or pharmacy payments should never receive payment-card data, account credentials, or verification codes.\u003C\u002Fp>\n\u003Ch2>How Many People Were Affected and How Did WIRX Respond?\u003C\u002Fh2>\n\u003Cp>The source-linked regulatory record reports 20,047 people nationwide. It includes 693 Texas residents, eight Massachusetts residents, four Maine residents, and one New Hampshire resident; those are subsets of the national figure and are not added to it again. Notifications began reaching state agencies and HHS around February 12, 2026.\u003C\u002Fp>\n\u003Cp>WIRX assessed system security, reviewed policies and procedures, notified potentially affected people, and informed federal law enforcement. The company recommends monitoring account statements, explanation-of-benefits statements, and free credit reports. Questions may be directed to 833-918-1152 on weekdays from 8 a.m. to 8 p.m. CST using engagement number B159052. LeakData does not host incident files or personal records.\u003C\u002Fp>","Official WIRX Pharmacy notice confirming unauthorized access to or acquisition of files containing PII and PHI, with regulatory records reporting 20,047 people",false,"Medium","completed","\u002Fuploads\u002Flogo\u002Fwirxpharmacy_com.jpg"]