Clustered 18 filings across 7 jurisdictions · filing window Mar 24, 2023 → Jun 28, 2023. View entity profile → Other incidents for this victim →
incident inc_57db4e2f801d4517 · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Identity (basic) · Government ID · Financial account
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
CA DE ME MT NH OR WA
all State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
18 filings across 7 jurisdictions · Mar 24, 2023 – Jun 28, 2023 · 4 milestones
Feb 1, 2023
When the intrusion reportedly occurred, per the linked filings
Feb 4, 2023
Reported by MAINE AG, CALIFORNIA AG, OREGON AG, DELAWARE AG, WASHINGTON AG, NEW HAMPSHIRE AG filings
Mar 15, 2023
Reported by NEW HAMPSHIRE AG filing
Apr 26, 2023
Reported by MAINE AG filing
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
NCB Management Services, Inc. reported unauthorized access to its systems on February 1, 2023, discovered on February 4, 2023. The incident potentially exposed personal and financial information of former Bank of America credit card customers, including names, addresses, SSNs, and account numbers. NCB engaged federal law enforcement and offered two years of identity theft protection via Experian.
NCB Management Services, Inc., a financial services company and a vendor for Bank of America, experienced an external system breach (hacking) on February 1, 2023. The breach was discovered on February 4, 2023. The incident resulted in the compromise of names and driver's license or non-driver identification card numbers for 494,969 individuals, including 1,925 residents of Maine. Affected individuals were notified on March 24, 2023, and offered 24 months of identity theft protection services through Experian.
Affected (this filing): 1,925
NCB Management Service, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-03-24. The breach occurred during 2/1/2023 - 2/6/2023. The breach was discovered on 2/4/2023. 494,969 individuals were affected. Notice was sent on 3/24/2023.
Affected (this filing): 494,969
NCB Management Services, Inc. notified affected individuals of a data breach occurring February 1, 2023, discovered February 4, 2023. An unauthorized party accessed systems containing closed Bank of America credit card account data, including names, SSNs, driver's license numbers, and financial account details. NCB worked with federal law enforcement and provided two years of Experian IdentityWorks protection. The incident is contained.
NCB Management Services, Inc. reported a data breach affecting approximately 1,000 individuals in New Hampshire. The incident involved unauthorized access to a public-facing application, resulting in the exfiltration of personal information including names and government-issued IDs. The company engaged forensic investigators, notified law enforcement, and offered credit monitoring services.
Affected (this filing): 1,000
NCB Management Services, Inc. disclosed a data breach where an unauthorized party accessed systems containing confidential client account information between February 1 and February 4, 2023. The incident involved potentially accessed data related to closed Bank of America credit card accounts, including names, addresses, SSNs, driver's license numbers, and financial account details. NCB worked with federal law enforcement, stopped the unauthorized activity, and provided affected individuals with two years of complimentary identity theft protection via Experian.
NCB Management Services, Inc. notified affected individuals of a data breach occurring February 1, 2023, discovered February 4, 2023. An unauthorized party accessed systems containing closed Bank of America credit card account data, including names, SSNs, driver's license numbers, and financial account details. NCB worked with federal law enforcement and provided two years of Experian IdentityWorks protection. The incident is contained.
NCB Management Services, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-05-22. 1,087,842 individuals were affected.
Affected (this filing): 1,087,842
NCB Management Services, Inc reported a data breach to the Montana Attorney General. The breach was reported on 2023-05-22. The breach occurred from 2/1/2023 to 2/4/2023. 2,594 Montana residents were affected.
Affected (this filing): 2,594
NCB Management Services, Inc. notified the NH Attorney General of a security incident where an unauthorized party accessed systems on Feb 1, 2023, discovered on Feb 4, 2023. The breach affected approx. 2,938 NH residents, exposing names and other PII. NCB contained the intrusion, engaged forensic experts, notified law enforcement, and provided 2 years of Kroll identity monitoring. Remediation included enhanced network monitoring, access controls, and employee training.
Affected (this filing): 2,938
NCB Management Services, Inc. reported that an unauthorized party gained access to its systems on February 1, 2023, which was discovered on February 4, 2023. The breach affected confidential client account information, potentially including names and financial account details. NCB contained the intrusion, implemented additional security measures, and offered two years of identity monitoring via Kroll. The company is cooperating with federal law enforcement.
NCB Management Services, Inc., a finance sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2023-02-04 and filed notice on 2023-05-22. 15,899 Washington residents were affected. 107 days elapsed between awareness and notification. 3 days to identify the breach. 2 days to contain the breach.
Affected (this filing): 15,899
NCB Management Services, Inc. reported an external system breach (hacking) occurring between Feb 1-6, 2023, discovered on Feb 4, 2023. The incident affected 1,087,842 individuals, including 3,261 Maine residents. Compromised data included names and financial account numbers. NCB notified consumers in writing on May 19, 2023, and provided 24 months of identity monitoring through Kroll.
Affected (this filing): 1,087,842
NCB Management Services, Inc., a third-party accounts receivable provider for Capital One, reported that an unauthorized third party accessed its systems on February 1, 2023, discovered on February 4, 2023. The incident affected 53 New Hampshire residents, exposing names and credit card account information. NCB engaged Kroll for credit monitoring and cooperated with law enforcement.
Affected (this filing): 53
NCB Management Services, Inc reported a data breach to the Montana Attorney General. The breach was reported on 2023-05-26. The breach occurred from 2/1/2023 to 2/4/2023. 215 Montana residents were affected.
Affected (this filing): 215
Capital One, a financial services company, reported a data breach that occurred at a third-party vendor, NCB Management Services, Inc. The breach, an external system intrusion (hacking), took place from February 1, 2023, to February 4, 2023, and was discovered on April 26, 2023. It affected 222 Maine residents. The compromised information included names combined with financial account or credit/debit card numbers and their security codes. In response, the vendor is offering two years of identity monitoring services through Kroll.
Affected (this filing): 222
NCB Management Services, Inc. issued a supplemental notice regarding a cybersecurity incident where an unauthorized party accessed confidential client account information between February 1 and February 4, 2023. The breach affected approximately 3,500 Rhode Island residents (and potentially others across multiple states) whose names and government identifiers (SSN, DOB, driver's license) were accessed. NCB contained the breach, cooperated with federal law enforcement, and provided two years of complimentary Kroll identity monitoring services.
Affected (this filing): 3,500
NCB Management Services, Inc. notified the NH Attorney General of a security incident where an unauthorized party accessed systems on Feb 1, 2023, discovered on Feb 4, 2023. Approximately 2,938 NH residents were affected. Data included names and other PII. NCB contained the breach, engaged forensic experts, notified law enforcement, and provided 2 years of Kroll identity monitoring.
Affected (this filing): 2,938