NCH CORPORATION
bd_1baf0331620d3d06 · schema v1 · pii pii-v1
Full breach record for NCH CORPORATION →4 incidents on fileThreat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Embargo on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
Your leading global experts in industrial solutions. At NCH Corporation, we don’t just sell products—we deliver solutions that keep businesses moving. For ov... - More than 7.3TB of data has been downloaded.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Mar 9, 2026
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- New Hampshire State AGbd_2a8be8acf60543c62026-05-01 · +52dVerified by operator
- Vermont State AGbd_4194fd4f05a95e972026-05-01 · +52dVerified by operator
- Maine State AGbd_43ee4726090e90612026-05-01 · +52dVerified
- Indiana State AGbd_b1ef5142cadc51242026-05-01 · +52dVerified by operator
Show 6 more filings ↓Show fewer ↑up to 95d gap
- Massachusetts State AGbd_df70bf7a043fe76e2026-05-01 · +52dVerified by operator
- Nebraska State AGbd_f4b9cb299ae5fa902026-05-01 · +52dVerified by operator
- Texas State AGbd_f1f602a50bc76d642026-05-05 · +56dVerified
- Texas State AGbd_36bfa79ae2b695442025-12-09 · +91dVerified
- Massachusetts State AGbd_42dfca2c52713f4a2025-12-05 · +95dVerified
- New Hampshire State AGbd_468c94ee52fa3fc52025-12-05 · +95dVerified
Showing first 10 of 17 linked disclosures.
Filing propagation · 11 filings · 7 states
View merged incident ↗Pattern: first filing Dec 5 (MA), last May 5 (TX) — a 151-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Cascade drawn from the first 10 linked disclosures of 17 — the full spread may be wider.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
embargo
According to ransomware.live, Embargo is a Rust-based ransomware-as-a-service group that emerged in April 2024, primarily targeting US healthcare, manufacturing, and business services organizations using double extortion, assessed as a potential successor to BlackCat/ALPHV with over $34 million in ransom proceeds.