NASCO Industries Inc
bd_5dcd476cd7204fbf · schema v1 · pii pii-v1
Full breach record for NASCO Industries Inc →NASCO, a benefits administration services provider for health plans, experienced a data security incident on May 30, 2023, involving its third-party file-sharing application, MOVEit Transfer by Progress Software. A threat actor exploited a vulnerability in MOVEit to acquire data. NASCO discovered the incident on July 12, 2023. Affected data includes personal and health information of health plan members. NASCO decommissioned the affected server, discontinued MOVEit use, engaged forensic investigators, notified law enforcement, and is offering 24 months of identity monitoring via Experian.
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_3b3b709830689a45Maine State AGfiled 2024-01-10Candidate
- bd_d55aa1ea3b2002afVermont State AGfiled 2024-01-08(2d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-579196
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 10, 2024
- Raw hash
- 78d085bbdad42ca2fb0b0d9710355ac90ede8ff0f30765df295f7b3f1454f445
Reporting entity
- Name
- NASCO Industries Incnorm: nasco industries
- Domain
- nasco.com
Victim entity
- Name
- NASCO Industries Incnorm: nasco industries
- Domain
- nasco.com
Incident
- Discovered
- Jul 12, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Notified law enforcement authorities
- Third party
- via Progress Software
- Initial access
- supply_chain
Compliance
- Time to disclose
- 26 weeks(182 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.