Social EngineeringPhishingBECEmployee Data InvolvedData ExfiltratedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
NSC Technologies
bd_80a17f46d0119d9b · schema v1 · pii pii-v1
Full breach record for NSC Technologies →NSC Technologies, LLC experienced a Business Email Compromise (BEC) incident on March 2, 2017. An external actor spoofed the CEO's email address and directed the payroll department to send employee W-2 forms. The request was identified as fraudulent moments after the data was sent. The breach exposed employees' names, addresses, Social Security Numbers, and 2016 income/withholding information. NSC notified law enforcement, the FTC, and the IRS, and provided one year of identity theft protection to affected employees.
California clockDiscovered Mar 2, 2017 → Notified Mar 6, 20174d ✓ CA 60-day OK14 days discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-66949
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 16, 2017
- Raw hash
- af1422423c1254405d1888d11896e28a0e1a9f58d087141e480bb02a0ecc9662
Reporting entity
- Name
- NSC Technologiesnorm: nsc technologies
- Domain
- nsc-tech.com
Victim entity
- Name
- NSC Technologiesnorm: nsc technologies
- Domain
- nsc-tech.com
Incident
- Discovered
- Mar 2, 2017
- Materiality determined
- —
- Notification sent
- Mar 6, 2017
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified appropriate federal, state, and local law enforcement agenciesAlerted the Federal Trade CommissionAlerted the federal Internal Revenue Service
- Initial access
- phishing_link
Compliance
- Time to disclose
- 14 days(14 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 4d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 2, 2017→ Notified: Mar 6, 20174d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.