HackingStolen CredentialsCustomer Data InvolvedData ExfiltratedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
NCH CORPORATION
bd_df70bf7a043fe76e · schema v1 · pii pii-v1
Full breach record for NCH CORPORATION →NCH Corporation, an industrial maintenance and hygiene solutions provider, notified Massachusetts residents of a cybersecurity incident involving unauthorized access to human resources files. The breach exposed names, Social Security numbers, dates of birth, and potentially financial, payment card, and medical information for current and former employees and their dependents. NCH engaged IDX to provide two years of complimentary identity protection services and enhanced its security measures.
Leak gap clock⏱ Leak >90d
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
This filing is one of 4 about the same incident.View merged incident
A leak claim by cl0p about this victim predates this filing by 160 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_1baf0331620d3d06Leak Siteembargofiled 2026-03-09(52d gap)Verified
Regulatory filings (2) · sorted by filing gap
- bd_43ee4726090e9061Maine State AGfiled 2026-05-01Verified
- bd_f1f602a50bc76d64Texas State AGfiled 2026-05-05(4d gap)Verified
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-677-nch-corporation/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 1, 2026
- Raw hash
- dbf2e26aae23932797bd40534754890715972cc1ea339a409a4574776992d5c9
Reporting entity
- Name
- NCH CORPORATIONnorm: nch
- Domain
- nch.com
Victim entity
- Name
- NCH CORPORATIONnorm: nch
- Domain
- nch.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Compliance flags
- Leak >90d
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.