Alliance Healthcare Allegedly Breached as 138,000 Pharmacy CRM Records Claimed

A threat actor claims to have breached Alliance Healthcare, alleging the exposure of 138,000 pharmacy CRM records containing customer accounts and prescription-related metadata.
Screenshot of a forum post alleging a data breach involving Alliance Healthcare (AAH), claiming 138,000 exposed records including pharmacy customer account information and prescription-related data. Portions of the sample data have been blurred by BreachNews.
Screenshot of the forum post in which a threat actor claims to have breached Alliance Healthcare (AAH) and stolen approximately 138,000 records. BreachNews blurred the published data samples to avoid reproducing sensitive information.

A threat actor is claiming to have breached Alliance Healthcare (AAH), one of the UK’s largest pharmaceutical wholesalers, alleging the exposure of approximately 138,000 records containing pharmacy customer account information and prescription-related metadata. The claim remains unverified at time of publication.

Alliance Healthcare supplies medicines and pharmacy services to independent pharmacies, NHS trusts, hospitals, and care homes across the United Kingdom, making it a key organization within the country’s pharmaceutical supply chain.

Alleged CRM data includes pharmacy accounts and prescription metadata

According to the threat actor, the allegedly stolen dataset contains CRM records associated with pharmacy customers rather than individual patient accounts. The listing claims the data includes company names, shipping and billing addresses, telephone numbers, Alliance Healthcare account numbers, ANA numbers, UDI identifiers, account types, customer portal status, CRM notes, parent account relationships, and internal risk classifications.

The actor also claims the dataset contains prescription-related records including prescription numbers, prescription types, issue dates, barcode identifiers, and pack counts.

Samples reviewed by BreachNews appear consistent with Salesforce export data and include custom CRM objects alongside pharmacy account records. Several sample records reference NHS trusts, hospital pharmacy departments, and independent pharmacies throughout the UK.

Internal operational records could aid reconnaissance

Beyond basic account information, the alleged dataset contains internal CRM notes describing customer relationships, operational instructions, sales activity, pharmacy contacts, and account-specific observations.

While the exposed records do not appear to contain complete patient medical records based on the published samples, internal business intelligence of this nature could still provide valuable information for social engineering, business email compromise, or future attacks targeting pharmacies and healthcare providers.

The range of records also suggests the threat actor claims to have accessed multiple areas of Alliance Healthcare’s CRM environment rather than exporting a single customer database. Sample records reviewed by BreachNews contain modification timestamps extending into April 2026, indicating the alleged dataset may include relatively recent business information.

No public confirmation from Alliance Healthcare

Alliance Healthcare had not issued any public statement at time of publication regarding the alleged breach.

As with similar marketplace listings, the authenticity, scope, and origin of the claimed dataset have not been independently verified. It also remains unclear how the threat actor allegedly obtained access or whether the records represent current production data.

Related healthcare breaches

The healthcare sector continues to face sustained cyber threats targeting providers, suppliers, and healthcare technology platforms. BreachNews coverage from earlier this year includes an alleged AgelessRx telehealth database breach, the confirmed Xsolis phishing-related data breach, and CareCloud’s confirmed electronic health records breach.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site
INTEL.BREACHNEWS.COM

Live Cyber
Threat Map

Explore live cyber activity, recent breach reports, KEV alerts, and public threat feeds from a single interactive dashboard.

Launch Threat Map