DisclosureLens
MalwareHealthcareTechnologyHealthcareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedSupply Chain (3P Vendor)AuthenticationCredentialsFinancial accountHealth (basic)Identity (basic)Government IDPHIMediumContained

Nexelis Group

bd_72583f487ec71f08 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Nov 8, 2020

Filed

Apr 8, 2021

To disclose

22 weeks

Affected

957state residents only

Confidence

68%
Full breach record for Nexelis Group

Nexelis Group reported a ransomware incident affecting data from its acquired subsidiary, Pacific Biomarkers. Unauthorized access occurred from September 26 to November 9, 2020. Nexelis discovered the incident on November 8, 2020. The breach compromised personal information of 957 Washington residents, including SSNs, driver's licenses, medical info, and payment card data. Nexelis engaged forensic investigators, notified the FBI and RCMP, and offered 12 months of identity monitoring.

Washington clock WA AG >90d22 weeks discovery → filing
AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.

Incident timeline

undetected · 43 days
discovery → filing · 22 weeks / 151 days

Sep 26, 2020

Begins

Nov 8, 2020

Discovered

Apr 8, 2021

Filed

vs. sector median

+9 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed957 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.