A threat actor is claiming to have breached Alliance Healthcare (AAH), one of the UK’s largest pharmaceutical wholesalers, alleging the exposure of approximately 138,000 records containing pharmacy customer account information and prescription-related metadata. The claim remains unverified at time of publication.
Alliance Healthcare supplies medicines and pharmacy services to independent pharmacies, NHS trusts, hospitals, and care homes across the United Kingdom, making it a key organization within the country’s pharmaceutical supply chain.
Alleged CRM data includes pharmacy accounts and prescription metadata
According to the threat actor, the allegedly stolen dataset contains CRM records associated with pharmacy customers rather than individual patient accounts. The listing claims the data includes company names, shipping and billing addresses, telephone numbers, Alliance Healthcare account numbers, ANA numbers, UDI identifiers, account types, customer portal status, CRM notes, parent account relationships, and internal risk classifications.
The actor also claims the dataset contains prescription-related records including prescription numbers, prescription types, issue dates, barcode identifiers, and pack counts.
Samples reviewed by BreachNews appear consistent with Salesforce export data and include custom CRM objects alongside pharmacy account records. Several sample records reference NHS trusts, hospital pharmacy departments, and independent pharmacies throughout the UK.
Internal operational records could aid reconnaissance
Beyond basic account information, the alleged dataset contains internal CRM notes describing customer relationships, operational instructions, sales activity, pharmacy contacts, and account-specific observations.
While the exposed records do not appear to contain complete patient medical records based on the published samples, internal business intelligence of this nature could still provide valuable information for social engineering, business email compromise, or future attacks targeting pharmacies and healthcare providers.
The range of records also suggests the threat actor claims to have accessed multiple areas of Alliance Healthcare’s CRM environment rather than exporting a single customer database. Sample records reviewed by BreachNews contain modification timestamps extending into April 2026, indicating the alleged dataset may include relatively recent business information.
No public confirmation from Alliance Healthcare
Alliance Healthcare had not issued any public statement at time of publication regarding the alleged breach.
As with similar marketplace listings, the authenticity, scope, and origin of the claimed dataset have not been independently verified. It also remains unclear how the threat actor allegedly obtained access or whether the records represent current production data.
Related healthcare breaches
The healthcare sector continues to face sustained cyber threats targeting providers, suppliers, and healthcare technology platforms. BreachNews coverage from earlier this year includes an alleged AgelessRx telehealth database breach, the confirmed Xsolis phishing-related data breach, and CareCloud’s confirmed electronic health records breach.












