The NOCO Company
bd_09da81db733948c9 · schema v1 · pii pii-v1
Full breach record for The NOCO Company →The NOCO Company identified malicious code on its website (no.co) on March 23, 2021, which allowed an unauthorized party to access payment card information, names, usernames, and passwords of customers who made purchases between October 8, 2019, and March 23, 2021. The company removed the code, engaged a cybersecurity firm, reset passwords, and implemented additional security controls.
J jump to incidentP pin to compareR raw source
Incident timeline
Oct 8, 2019
Begins
Mar 23, 2021
Discovered
May 18, 2021
Filed
vs. sector median
on median
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Montana State AGbd_141af2953e8ba7592021-05-18Verified
- Indiana State AGbd_3c5747c7c6d831e22021-05-18Verified
- New Hampshire State AGbd_77294e280b3148f32021-05-18Verified
- Maine State AGbd_b96d97e8ca5f53382021-05-18Verified
Show 1 more filing ↓Show fewer ↑
- Massachusetts State AGbd_cc8b163925f425052021-05-18Verified
Filing propagation · 6 filings · 6 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.