NASCO Industries Inc
bd_da6299b7281a604f · schema v1 · pii pii-v1
Full breach record for NASCO Industries Inc →NASCO, a benefits administration services provider for health plans, experienced a data security incident on May 30, 2023, involving its third-party file-sharing application, MOVEit Transfer by Progress Software. A threat actor exploited a vulnerability in MOVEit to acquire data, including personal and health information of NASCO's health plan customers. NASCO discovered the incident on July 12, 2023, and promptly secured its systems, launched a forensic investigation, and notified law enforcement. The affected MOVEit server was decommissioned. NASCO is offering 24 months of complimentary identity monitoring and credit monitoring services to affected individuals.
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_a10a2ec406bd2fd7Vermont State AGfiled 2023-10-27Verified
- bd_e11296a5b32dc0baNew Hampshire State AGfiled 2023-10-25(2d gap)Verified
- bd_70967d52d87f8c3aNew Hampshire State AGfiled 2023-11-03(7d gap)Verified
- bd_7726748f55cf2ae9Maine State AGfiled 2023-10-20(7d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-575825
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 27, 2023
- Raw hash
- b5dfb4273658eab916669a41ff5c526bf01611b009d5fdd9def2471c544a2b6f
Reporting entity
- Name
- NASCO Industries Incnorm: nasco industries
- Domain
- nasco.com
Victim entity
- Name
- NASCO Industries Incnorm: nasco industries
- Domain
- nasco.com
Incident
- Discovered
- Jul 12, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified California Attorney General
- Third party
- via Progress Software
- Initial access
- supply_chain
Compliance
- Time to disclose
- 15 weeks(107 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.