DisclosureLens
Social EngineeringTechnologyInformationPhishingBECEmployee Data InvolvedData ExfiltratedGovernment IDIdentity (basic)Financial accountMediumContained

NSC Technologies

bd_80a17f46d0119d9b · schema v1 · pii pii-v1

Severity

Medium

Discovered

Mar 2, 2017

Filed

Mar 16, 2017

To disclose

14 days

Affected

Not disclosed

Confidence

65%
Full breach record for NSC Technologies2 incidents on file

NSC Technologies, LLC experienced a Business Email Compromise (BEC) incident on March 2, 2017. An external actor spoofed the CEO's email address and directed the payroll department to send employee W-2 forms. The request was identified as fraudulent moments after the data was sent. The breach exposed employees' names, addresses, Social Security Numbers, and 2016 income/withholding information. NSC notified law enforcement, the FTC, and the IRS, and provided one year of identity theft protection to affected employees.

California clockDiscovered Mar 2, 2017Notified Mar 6, 20174d CA 60-day OK14 days discovery → filing

Incident timeline

discovery → filing · 14 days

Mar 2, 2017

Begins

Mar 2, 2017

Discovered

Mar 16, 2017

Filed

vs. sector median

17 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.