Clustered 5 filings across 4 jurisdictions · filing window Oct 20, 2023 → Nov 3, 2023. View entity profile → Other incidents for this victim →
incident inc_56a8cdfabc2a4271 · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
Government ID
CA ME NH VT
all State AG
Earliest sighting first · deep chronology in Litigation Timeline
May 30, 2023
When the intrusion reportedly occurred, per the linked filings
Jul 12, 2023
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Reported by VERMONT AG, CALIFORNIA AG filings
Aug 21, 2023
Reported by MAINE AG, NEW HAMPSHIRE AG filings
Healthcare organization NASCO reported an external system breach that occurred on May 30, 2023, and was discovered on August 21, 2023. The breach affected one Maine resident, compromising their Social Security Number. NASCO provided written notification to the affected individual on October 20, 2023, and offered 24 months of identity monitoring services through Experian.
Affected (this filing): 1
State of New Hampshire Attorney General's office received a breach notification from NASCO on October 25, 2023. The attached PDF document is empty (6 pages of blank content). No specific details regarding the nature of the breach, affected data, or incident dates are provided in the visible text.
NASCO, a healthcare benefits administrator, disclosed a cybersecurity incident involving its MOVEit Transfer file-sharing application. A threat actor exploited the application on May 30, 2023, acquiring personal information of health plan members. NASCO discovered the incident on July 12, 2023, decommissioned the affected server, engaged forensic investigators, and notified law enforcement. Affected individuals were offered 24 months of credit monitoring.
NASCO, a benefits administration services provider for health plans, experienced a data security incident on May 30, 2023, involving its third-party file-sharing application, MOVEit Transfer by Progress Software. A threat actor exploited a vulnerability in MOVEit to acquire data, including personal and health information of NASCO's health plan customers. NASCO discovered the incident on July 12, 2023, and promptly secured its systems, launched a forensic investigation, and notified law enforcement. The affected MOVEit server was decommissioned. NASCO is offering 24 months of complimentary identity monitoring and credit monitoring services to affected individuals.
NASCO, a supplier of educational and agricultural products, notified the New Hampshire Department of Justice on November 3, 2023, regarding unauthorized access to its network discovered on August 21, 2023. The incident potentially compromised employees' and customers' personal information. NASCO engaged forensic investigators and law enforcement.