HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICHighContained
National Center for Construction Education and Research
bd_9edfbca4d61fe99b · schema v1 · pii pii-v1
Full breach record for National Center for Construction Education and Research →National Center for Construction Education (NCCER) disclosed a data breach detected in March 2025 involving unauthorized access to its network. The incident compromised the personal information of approximately 15,193 individuals, including names, Social Security numbers, and dates of birth. NCCER conducted a data-mining review to identify affected individuals, notifying state regulators including Massachusetts (Doc 2026-851). The breach involved the potential theft of identity and government-issued data.
Massachusetts clock✗ MA AG >90d14 months discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_c8e7a1544e3679b0Indiana State AGfiled 2026-05-01Verified
- bd_f9cb8264eb3744d6Maine State AGfiled 2026-05-22(21d gap)Verified
- bd_82a8f37e401323f1Texas State AGfiled 2026-05-28(27d gap)Verified by operator
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-851-national-center-for-construction-education/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 1, 2026
- Raw hash
- be1a850c62aa778c7df7551335a529dc961d5ea6d79d1938515d907ea73b314b
Reporting entity
- Name
- National Center for Construction Education and Researchnorm: national center for construction education and research
Victim entity
- Name
- National Center for Construction Education and Researchnorm: national center for construction education and research
Incident
- Discovered
- Mar 1, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 15,193
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Filed breach notification with Massachusetts Office of Consumer Affairs and Business Regulation (Document 2026-851)
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 14 months(426 days from discovery to filing)
- Compliance flags
- MA AG >90d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.