NASCO Industries Inc
bd_5dcd476cd7204fbf · schema v1 · pii pii-v1
Full breach record for NASCO Industries Inc →6 incidents on fileNASCO, a benefits administration services provider for health plans, experienced a data security incident on May 30, 2023, involving its third-party file-sharing application, MOVEit Transfer by Progress Software. A threat actor exploited a vulnerability in MOVEit to acquire data. NASCO discovered the incident on July 12, 2023. Affected data includes personal and health information of health plan members. NASCO decommissioned the affected server, discontinued MOVEit use, engaged forensic investigators, notified law enforcement, and is offering 24 months of identity monitoring via Experian.
J jump to incidentP pin to compareR raw source
Incident timeline
May 30, 2023
Begins
Jul 12, 2023
Discovered
Jan 10, 2024
Filed
vs. sector median
+13 wks slower
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Maine State AGbd_3b3b709830689a452024-01-10Candidate
- Vermont State AGbd_d55aa1ea3b2002af2024-01-08 · +2dVerified
Filing propagation · 3 filings · 3 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.