NASCO Industries Inc
bd_a10a2ec406bd2fd7 · schema v1 · pii pii-v1
Full breach record for NASCO Industries Inc →6 incidents on fileNASCO, a healthcare benefits administrator, disclosed a cybersecurity incident involving its MOVEit Transfer file-sharing application. A threat actor exploited the application on May 30, 2023, acquiring personal information of health plan members. NASCO discovered the incident on July 12, 2023, decommissioned the affected server, engaged forensic investigators, and notified law enforcement. Affected individuals were offered 24 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
May 30, 2023
Begins
Jul 12, 2023
Discovered
Oct 27, 2023
Filed
vs. sector median
+3 wks slower
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitedispossessorbd_c465e200e2f131f92022-12-20 · +311dVerified by operator
Regulatory filings (5) · sorted by filing gap
- California State AGbd_da6299b7281a604f2023-10-27Verified
- New Hampshire State AGbd_e11296a5b32dc0ba2023-10-25 · +2dVerified
- Maine State AGbd_7726748f55cf2ae92023-10-20 · +7dCandidate
- Massachusetts State AGbd_90d1886d8d6302292023-10-20 · +7dVerified
Show 1 more filing ↓Show fewer ↑up to 17d gap
- HHS OCRbd_d79917b33aef60e82023-10-10 · +17dVerified by operator
Filing propagation · 6 filings · 6 states
View merged incident ↗Pattern: first filing Oct 10 (GA), last Oct 27 (VT) — a 17-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.