NCI Group, Inc.
bd_22b9837a22b5c6b6 · schema v1 · pii pii-v1
Full breach record for NCI Group, Inc. →NCI Group, Inc. notified Montana residents that on August 8, 2017, an unknown individual accessed three employee email accounts via phishing, exposing customer names and Social Security numbers. NCI engaged forensic investigators and Kroll for one year of identity monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Aug 8, 2017
Discovered
Sep 22, 2017
Filed
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- New Hampshire State AGbd_5ca2b80824c23f5f2017-09-22Verified
- Massachusetts State AGbd_c798fed4bb2e84402017-09-22Verified
- Massachusetts State AGbd_a9dac6d5c6c1f63e2017-10-10 · +18dVerified by operator
Filing propagation · 4 filings · 3 states
View merged incident ↗Pattern: first filing Sep 22 (NH), last Oct 10 (MA) — a 18-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.