MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTCREDENTIALSMediumContained
National Board for Certified Counselors, Inc.
bd_ed724bb2b0de3c04 · schema v1 · pii pii-v1
Full breach record for National Board for Certified Counselors, Inc. →National Board for Certified Counselors, Inc. (NBCC) disclosed a cybersecurity incident occurring between August 31 and September 7, 2020. An unauthorized actor introduced malware that encrypted files and exfiltrated personal data, including names, addresses, Social Security numbers, dates of birth, and credential information. NBCC engaged third-party forensic investigators, notified the FBI, and offered 12 months of credit monitoring via TransUnion. The incident was discovered on September 7, 2020, and notification letters were issued in 2021.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_2c41a7e342598fe9Montana State AGfiled 2021-01-12(1d gap)Candidate
- bd_3b308b49ee1b5741Maine State AGfiled 2021-01-12(1d gap)Verified
- bd_3e380c527a1439a3California State AGfiled 2021-01-12(1d gap)Verified
- bd_8c92c2d72fb93b57Washington State AGfiled 2021-01-12(1d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 1d gap
- bd_af7418f535af9665Delaware State AGfiled 2021-01-12(1d gap)Verified
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Business%20Resources%20Laws/Related%20Laws/Breaches/2021/NationalBoardCertifiedCounselors.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 13, 2021
- Raw hash
- 59ecb3623f60a3c799e0d6f62d2d69a6f5536899c3849a91551182c40844ecea
Reporting entity
- Name
- National Board for Certified Counselors, Inc.norm: national board for certified counselors
Victim entity
- Name
- National Board for Certified Counselors, Inc.norm: national board for certified counselors
Incident
- Discovered
- Sep 7, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTCREDENTIALS
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- notifying regulatory authorities, as required by law
Compliance
- Time to disclose
- 18 weeks(128 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.