DisclosureLens
HackingEnergy & UtilitiesProfessional ServicesUtilitiesVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedIdentity (basic)Government IDMediumContained

Neste USA, Inc

bd_288c64598bacc330 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Nov 30, 2023

Filed

Dec 27, 2023

To disclose

27 days

Affected

1state residents only

Linked

2 filings

Confidence

66%
Full breach record for Neste USA, Inc

Neste USA, Inc. notified Montana residents that its vendor, Paycor Inc., experienced a data security incident involving the MOVEit file-transfer software. Paycor was attacked via an unknown vulnerability on May 31, 2023. Neste learned of the incident on November 30, 2023. Paycor informed Neste that customers' names, dates of birth, and Social Security numbers may have been accessed. Neste is offering credit monitoring services.

Incident timeline

undetected · 183 days
discovery → filing · 27 days

May 31, 2023

Begins

Nov 30, 2023

Discovered

Dec 27, 2023

Filed

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
Massachusetts State AGDec 27 · first
Montana State AGDec 27 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.