NCH CORPORATION
bd_fa9e8c6267f933c4 · schema v1 · pii pii-v1
Full breach record for NCH CORPORATION →4 incidents on fileThreat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Cl0p on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
NCH Software is a technology firm that provides a variety of software solutions and applications for different uses. Located in Canberra, Australia, the firm offers reliable, cost-effective, and user-friendly software that includes audio tools, video and business software, utilities and more. Some popular products include WavePad, Switch, and Doxillion. The company has a strong, global user base.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Nov 21, 2025
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Siteembargobd_1baf0331620d3d062026-03-09 · +108dVerified by operator
Regulatory filings (9) · sorted by filing gap
- Massachusetts State AGbd_42dfca2c52713f4a2025-12-05 · +13dVerified
- Texas State AGbd_36bfa79ae2b695442025-12-09 · +17dVerified
- New Hampshire State AGbd_2a8be8acf60543c62026-05-01 · +160dVerified by operator
- Vermont State AGbd_4194fd4f05a95e972026-05-01 · +160dVerified by operator
Show 5 more filings ↓Show fewer ↑up to 164d gap
- Maine State AGbd_43ee4726090e90612026-05-01 · +160dVerified
- Indiana State AGbd_b1ef5142cadc51242026-05-01 · +160dVerified by operator
- Massachusetts State AGbd_df70bf7a043fe76e2026-05-01 · +160dVerified by operator
- Nebraska State AGbd_f4b9cb299ae5fa902026-05-01 · +160dVerified by operator
- Texas State AGbd_f1f602a50bc76d642026-05-05 · +164dVerified
Showing first 10 of 17 linked disclosures.
Filing propagation · 10 filings · 7 states
View merged incident ↗Pattern: first filing Nov 21, last May 5 (TX) — a 164-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Cascade drawn from the first 10 linked disclosures of 17 — the full spread may be wider.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.