NASCO Industries Inc
ent_019e22649929979816c30964305d2d77
Disclosures
20
Leak Site · State AG · HHS OCR · 12 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
1,744,655
nationwide · HHS OCR GA
Leak-site claims
4
unverified actor claims
Identity resolution
- Canonical name
- NASCO Industries Inc
- Normalized
- nasco industries— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 25490000OV0CZYUZ7739
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- nasco.com
Disclosure history (20)newest first
- GLOBALLeak Siteas victim2026-06-29
- Maine State AGas reporting2024-01-10
NASCO, a healthcare services provider, experienced an external system breach on May 30, 2023, which was discovered on August 21, 2023. The breach impacted 4,489 Maine residents, compromising their names and Social Security numbers. The company began notifying affected individuals on October 2, 2023, and offered 24 months of identity monitoring services through Experian.
- California State AGas victim2024-01-10
NASCO, a benefits administration services provider for health plans, experienced a data security incident on May 30, 2023, involving its third-party file-sharing application, MOVEit Transfer by Progress Software. A threat actor exploited a vulnerability in MOVEit to acquire data. NASCO discovered the incident on July 12, 2023. Affected data includes personal and health information of health plan members. NASCO decommissioned the affected server, discontinued MOVEit use, engaged forensic investigators, notified law enforcement, and is offering 24 months of identity monitoring via Experian.
- Vermont State AGas victim2024-01-08
NASCO, a healthcare benefits administrator, disclosed a data breach involving its MOVEit Transfer file-sharing application. The incident occurred on May 30, 2023, and was discovered on July 12, 2023. Personal information of health plan members was accessed. NASCO engaged forensic investigators, notified law enforcement, decommissioned the affected server, and offered 24 months of credit monitoring via Experian IdentityWorks.
- New Hampshire State AGas victim2023-11-03
NASCO, a benefits administration provider, disclosed a supplemental breach to the NH AG regarding unauthorized access to its MOVEit Transfer instance on May 30, 2023. NASCO discovered the incident on July 12, 2023. The breach affected personal information of health plan members. NASCO notified 10,164 New Hampshire residents and offered credit monitoring.
- South Carolina State AGas victim2023-10-30
NASCO, a benefits administration provider, disclosed a cybersecurity incident involving its MOVEit Transfer instance. A threat actor acquired data from NASCO on May 30, 2023. NASCO discovered the incident on July 12, 2023. Personal information of health plan members was involved. NASCO engaged forensic investigators, notified law enforcement, decommissioned the affected server, and ceased using MOVEit. The company offered 24 months of Experian IdentityWorks to affected individuals.
- Maine State AGas victim2023-10-28
NASCO, a healthcare organization, reported an external system breach (hacking) that occurred on May 30, 2023, and was discovered on August 21, 2023. The breach affected 2,840 Maine residents, compromising their names and Social Security numbers. NASCO notified the affected individuals on October 27, 2023, and offered 24 months of identity monitoring services through Experian.
- Vermont State AGas victim2023-10-27
NASCO, a healthcare benefits administrator, disclosed a cybersecurity incident involving its MOVEit Transfer file-sharing application. A threat actor exploited the application on May 30, 2023, acquiring personal information of health plan members. NASCO discovered the incident on July 12, 2023, decommissioned the affected server, engaged forensic investigators, and notified law enforcement. Affected individuals were offered 24 months of credit monitoring.
- Oregon State AGas victim2023-10-27
NASCO reported a data breach to the Oregon Attorney General. The breach was reported on 2023-10-27. 804,862 individuals were affected.
- California State AGas victim2023-10-27
NASCO, a benefits administration services provider for health plans, experienced a data security incident on May 30, 2023, involving its third-party file-sharing application, MOVEit Transfer by Progress Software. A threat actor exploited a vulnerability in MOVEit to acquire data, including personal and health information of NASCO's health plan customers. NASCO discovered the incident on July 12, 2023, and promptly secured its systems, launched a forensic investigation, and notified law enforcement. The affected MOVEit server was decommissioned. NASCO is offering 24 months of complimentary identity monitoring and credit monitoring services to affected individuals.
- Washington State AGas victim2023-10-27
NASCO, a benefits administration provider, reported a supplemental breach to Washington AG regarding a MOVEit Transfer vulnerability exploited on May 30, 2023. NASCO discovered the incident on July 12, 2023. The breach affected personal information of approximately 12,986 individuals nationwide, including 7,100 Washington residents. NASCO engaged forensic investigators, notified law enforcement, decommissioned the affected server, and offered 24 months of credit monitoring.
- Montana State AGas victim2023-10-27
NASCO, a healthcare benefits administrator, notified Montana residents of a cybersecurity incident involving its MOVEit Transfer instance. A threat actor acquired personal information from NASCO's MOVEit server on May 30, 2023. NASCO discovered the incident on July 12, 2023, decommissioned the affected server, engaged forensic investigators, and notified law enforcement. Affected data included personal information of health plan members. NASCO offered 24 months of credit monitoring via Experian.
- New Hampshire State AGas victim2023-10-25
NASCO notified the NH Attorney General of a data security incident involving its MOVEit Transfer instance. Unauthorized access occurred on May 30, 2023, discovered July 12, 2023. The incident affected personal information of approximately 2 New Hampshire residents. NASCO engaged forensic investigators, notified law enforcement, and offered credit monitoring.
- Maine State AGas victim2023-10-20
Healthcare organization NASCO reported an external system breach that occurred on May 30, 2023, and was discovered on August 21, 2023. The breach affected one Maine resident, compromising their Social Security Number. NASCO provided written notification to the affected individual on October 20, 2023, and offered 24 months of identity monitoring services through Experian.
- Massachusetts State AGas victim2023-10-20
NASCO reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-10-20. 485,375 Massachusetts residents were affected. The report records the breach type as electronic.
- GEORGIAHHS OCRas victim2023-10-10
NASCO, a business associate, reported to HHS on October 10, 2023, a hacking incident that affected 1,744,655 individuals. The breach occurred on a network server and was caused by an exposed software application. The compromised protected health information (PHI) included names, dates of birth, addresses, Social Security numbers, diagnoses, and claims information. In response, NASCO provided complimentary credit monitoring and implemented enhanced security safeguards.
- GLOBALLeak Siteas victim2023-07-12
NASCO – NASCO is a healthcare company dedicated to co-creating digital health solutions for Blue Cross and Blue Shield companies.
- Illinois State AGas victim2023-01-01
NASCO filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-751). The register records the breach as discovered on May 30, 2023. Additional entities named: MOVEIT. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- GLOBALLeak Siteas victim2022-12-20
nasco.com
- GLOBALLeak Siteas victim2021-09-22
Supply-chain cascadesreviewed and confirmed
- NASCO Industries Inc’s filing is one of at least 97 in the Progress Software Corporation supply-chain incident (2023).