HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
NUCOR CORPORATION
bd_b6fb6e4436443cf8 · schema v1 · pii pii-v1
Full breach record for NUCOR CORPORATION →Nucor Corporation reported a data breach affecting 3 New Hampshire residents. Unauthorized third parties exploited a previously unknown vulnerability in a third-party file transfer software between May 26 and June 1, 2023, to acquire files containing personal information including names, addresses, Social Security numbers, and dates of birth. Nucor disabled access, applied a vendor fix, engaged forensic investigators, and offered credit monitoring services.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_6a06b9eb150003e9Maine State AGfiled 2023-07-03Candidate
- bd_f92fdb8fcfe3ebf1Vermont State AGfiled 2023-06-30(3d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/nucor-corporation-20230703.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 3, 2023
- Raw hash
- 4781fa5e10062583532259977f724ec1c10734f1d885a319257b5583fe6eb1f7
Reporting entity
- Name
- NUCOR CORPORATIONnorm: nucor
- Domain
- nucor.com
Victim entity
- Name
- NUCOR CORPORATIONnorm: nucor
- Domain
- nucor.com
Incident
- Discovered
- Jun 1, 2023
- Materiality determined
- —
- Notification sent
- Jun 30, 2023
- Affected individuals
- 3
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified state regulators
- Third party
- via third-party software vendor
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(32 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.