DisclosureLens
HackingHealthcareTechnologyHealthcareVulnerability ExploitData ExfiltratedTargetedPIIIdentity (basic)LowContained

NASCO Industries Inc

bd_ffb048d919d7530a · schema v1 · pii pii-v1

Severity

Low

Discovered

Jul 12, 2023

Filed

Oct 27, 2023

To disclose

15 weeks

Affected

680state residents only

Linked

7 filings

Confidence

66%
Full breach record for NASCO Industries Inc6 incidents on file

NASCO, a healthcare benefits administrator, notified Montana residents of a cybersecurity incident involving its MOVEit Transfer instance. A threat actor acquired personal information from NASCO's MOVEit server on May 30, 2023. NASCO discovered the incident on July 12, 2023, decommissioned the affected server, engaged forensic investigators, and notified law enforcement. Affected data included personal information of health plan members. NASCO offered 24 months of credit monitoring via Experian.

Incident timeline

undetected · 43 days
discovery → filing · 15 weeks / 107 days

May 30, 2023

Begins

Jul 12, 2023

Discovered

Oct 27, 2023

Filed

vs. sector median

+3 wks slower

This filing is one of 7 about the same incident.View merged incident

Linked disclosures

Why this link?

Ransomware claims (1)

Regulatory filings (5) · sorted by filing gap

Show 1 more filingup to 299d gap

Filing propagation · 6 filings · 6 states

View merged incident ↗
Illinois State AGJan 1 · first
Montana State AG+299d · this page

Pattern: first filing Jan 1 (IL), last Oct 30 (SC) — a 302-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.