MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTCREDENTIALSMediumContained
National Board for Certified Counselors, Inc.
bd_3e380c527a1439a3 · schema v1 · pii pii-v1
Full breach record for National Board for Certified Counselors, Inc. →National Board for Certified Counselors, Inc. (NBCC) disclosed a ransomware incident occurring between August 31 and September 7, 2020. Malware encrypted files and an unauthorized actor exfiltrated data including names, addresses, Social Security numbers, dates of birth, and credential information. NBCC engaged forensic investigators, notified the FBI, and offered 12 months of credit monitoring via TransUnion. The investigation concluded on December 28, 2020.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_2c41a7e342598fe9Montana State AGfiled 2021-01-12Candidate
- bd_3b308b49ee1b5741Maine State AGfiled 2021-01-12Verified
- bd_8c92c2d72fb93b57Washington State AGfiled 2021-01-12Verified
- bd_af7418f535af9665Delaware State AGfiled 2021-01-12Verified
Show 1 more filing ↓Show fewer ↑up to 1d gap
- bd_ed724bb2b0de3c04South Carolina State AGfiled 2021-01-13(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-198460
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 12, 2021
- Raw hash
- 4b4b46456d2297896cf7f97fd2cbc5e77154c5c1b43857df81f224de35b77edf
Reporting entity
- Name
- National Board for Certified Counselors, Inc.norm: national board for certified counselors
Victim entity
- Name
- National Board for Certified Counselors, Inc.norm: national board for certified counselors
Incident
- Discovered
- Sep 7, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTCREDENTIALS
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- notifying regulatory authorities, as required by law
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 18 weeks(127 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.