NASCO Industries Inc
bd_1a92f137101f29bd · schema v1 · pii pii-v1
Full breach record for NASCO Industries Inc →6 incidents on fileNASCO, a benefits administration provider, disclosed a cybersecurity incident involving its MOVEit Transfer instance. A threat actor acquired data from NASCO on May 30, 2023. NASCO discovered the incident on July 12, 2023. Personal information of health plan members was involved. NASCO engaged forensic investigators, notified law enforcement, decommissioned the affected server, and ceased using MOVEit. The company offered 24 months of Experian IdentityWorks to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
May 30, 2023
Begins
Jul 12, 2023
Discovered
Oct 30, 2023
Filed
vs. sector median
+3 wks slower
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitecl0pbd_8c1cb6cf621dcfa22023-07-12 · +110dVerified by operator
Regulatory filings (5) · sorted by filing gap
- Maine State AGbd_27541ee9c5b7e6e72023-10-28 · +2dCandidate
- Oregon State AGbd_aa31f139773717df2023-10-27 · +3dVerified
- Washington State AGbd_f61696cdfa81c4df2023-10-27 · +3dVerified by operator
- Montana State AGbd_ffb048d919d7530a2023-10-27 · +3dVerified by operator
Show 1 more filing ↓Show fewer ↑up to 302d gap
- Illinois State AGbd_1bc42ec569be8ced2023-01-01 · +302dVerified by operator
Filing propagation · 6 filings · 6 states
View merged incident ↗Pattern: first filing Jan 1 (IL), last Oct 30 (SC) — a 302-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.