MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTCREDENTIALSMediumActive
National Board for Certified Counselors, Inc.
bd_af7418f535af9665 · schema v1 · pii pii-v1
Full breach record for National Board for Certified Counselors, Inc. →National Board for Certified Counselors, Inc. (NBCC) disclosed a ransomware incident affecting 880 Delaware residents. Unauthorized access occurred between August 31 and September 7, 2020. The malware encrypted files and exfiltrated personal data including names, SSNs, DOBs, and credentials. NBCC engaged forensic investigators, notified the FBI, and provided 12 months of credit monitoring via TransUnion. Notification to residents began January 12, 2021.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_2c41a7e342598fe9Montana State AGfiled 2021-01-12Candidate
- bd_3b308b49ee1b5741Maine State AGfiled 2021-01-12Verified
- bd_3e380c527a1439a3California State AGfiled 2021-01-12Verified
- bd_8c92c2d72fb93b57Washington State AGfiled 2021-01-12Verified
Show 1 more filing ↓Show fewer ↑up to 1d gap
- bd_ed724bb2b0de3c04South Carolina State AGfiled 2021-01-13(1d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2021/01/NBCC-Notice-of-Data-Event-DE.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 12, 2021
- Raw hash
- 19d3d1a840946f74914654f53cccad038e96b5f2f7445ad1b79eb304b167a797
Reporting entity
- Name
- National Board for Certified Counselors, Inc.norm: national board for certified counselors
Victim entity
- Name
- National Board for Certified Counselors, Inc.norm: national board for certified counselors
Incident
- Discovered
- Sep 7, 2020
- Materiality determined
- —
- Notification sent
- Jan 12, 2021
- Affected individuals
- 880
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTCREDENTIALS
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the Federal Bureau of Investigation (FBI)
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 18 weeks(127 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.