NASCO Industries Inc
bd_ffb048d919d7530a · schema v1 · pii pii-v1
Full breach record for NASCO Industries Inc →6 incidents on fileNASCO, a healthcare benefits administrator, notified Montana residents of a cybersecurity incident involving its MOVEit Transfer instance. A threat actor acquired personal information from NASCO's MOVEit server on May 30, 2023. NASCO discovered the incident on July 12, 2023, decommissioned the affected server, engaged forensic investigators, and notified law enforcement. Affected data included personal information of health plan members. NASCO offered 24 months of credit monitoring via Experian.
J jump to incidentP pin to compareR raw source
Incident timeline
May 30, 2023
Begins
Jul 12, 2023
Discovered
Oct 27, 2023
Filed
vs. sector median
+3 wks slower
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitecl0pbd_8c1cb6cf621dcfa22023-07-12 · +107dVerified by operator
Regulatory filings (5) · sorted by filing gap
- Oregon State AGbd_aa31f139773717df2023-10-27Verified
- Washington State AGbd_f61696cdfa81c4df2023-10-27Verified by operator
- Maine State AGbd_27541ee9c5b7e6e72023-10-28 · +1dCandidate
- South Carolina State AGbd_1a92f137101f29bd2023-10-30 · +3dVerified
Show 1 more filing ↓Show fewer ↑up to 299d gap
- Illinois State AGbd_1bc42ec569be8ced2023-01-01 · +299dVerified by operator
Filing propagation · 6 filings · 6 states
View merged incident ↗Pattern: first filing Jan 1 (IL), last Oct 30 (SC) — a 302-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.