Ferring Pharmaceuticals Inc. recently experienced a data breach stemming from a phishing attack. On October 16, 2024, the company discovered suspicious activity linked to an employee's email account.
Upon investigation, it was determined that unauthorized access to the account may have exposed sensitive personal information. The breach was disclosed to the Massachusetts Attorney General's office on December 5, 2024, and impacted at least two individuals in the state.
The compromised data included:
The breach occurred when a phishing attack successfully targeted an employee's email account. This type of cyberattack typically involves tricking individuals into providing sensitive information or granting access to systems by posing as a legitimate entity. While the exact scope of the breach is still being assessed, the exposure of Social Security numbers and work-related details makes this incident particularly concerning.
You can review the official disclosure submitted to the Massachusetts Attorney General's office.
Ferring Pharmaceuticals acted promptly upon discovering the breach. The company immediately implemented a forced password reset for the affected email account and secured its email environment. A comprehensive internal investigation was launched to determine the extent of the breach, the specific data involved, and the individuals impacted. This review process concluded on October 28, 2024.
To mitigate the impact of the breach, Ferring Pharmaceuticals is offering affected individuals 18 months of complimentary identity protection services through Allstate Identity Protection's Pro+ Cyber plan. This service includes tri-bureau credit monitoring, dark web monitoring, financial transaction monitoring, and identity theft expense reimbursement of up to $1 million, among other features. Affected individuals will receive further instructions via email and mail regarding how to activate their identity protection benefits.
If you believe you may have been impacted by the Ferring Pharmaceuticals data breach, it is essential to take the following steps to protect your personal information:
A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.
This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.