Clustered 6 filings across 6 jurisdictions · filing window Jan 12, 2021 → Jan 13, 2021. View entity profile → Other incidents for this victim →
incident inc_dd850f2baf6d4daf · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
CA DE ME MT SC WA
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
all State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
Aug 31, 2020
When the intrusion reportedly occurred, per the linked filings
Sep 7, 2020
Reported by MAINE AG, CALIFORNIA AG, WASHINGTON AG, DELAWARE AG, SOUTH CAROLINA AG filings
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
National Board for Certified Counselors, Inc. reported a data breach to the Montana Attorney General. The breach was reported on 2021-01-12. The breach occurred from 8/31/2020 to 9/7/2020. 1,743 Montana residents were affected.
Affected (this filing): 1,743
National Board for Certified Counselors, Inc. reported a data breach affecting 2,410 Maine residents. The breach, which occurred between August 31, 2020, and September 7, 2020, was an external system breach (hacking). The compromised information included names in combination with Social Security numbers. The breach was discovered between September 7, 2020, and December 28, 2020. Affected individuals were notified on January 12, 2021, and offered 12 months of credit monitoring and identity restoration services through TransUnion.
Affected (this filing): 2,410
National Board for Certified Counselors, Inc. (NBCC) disclosed a ransomware incident occurring between August 31 and September 7, 2020. Malware encrypted files and an unauthorized actor exfiltrated data including names, addresses, Social Security numbers, dates of birth, and credential information. NBCC engaged forensic investigators, notified the FBI, and offered 12 months of credit monitoring via TransUnion. The investigation concluded on December 28, 2020.
National Board for Certified Counselors, Inc., a non-profit/charity sector entity reported a malware incident to the Washington Attorney General. The organization became aware of the incident on 2020-09-07 and filed notice on 2021-01-12. 9,898 Washington residents were affected. 127 days elapsed between awareness and notification. 7 days to identify the breach. 0 days to contain the breach.
Affected (this filing): 9,898
National Board for Certified Counselors, Inc. (NBCC) disclosed a ransomware incident affecting 880 Delaware residents. Unauthorized access occurred between August 31 and September 7, 2020. The malware encrypted files and exfiltrated personal data including names, SSNs, DOBs, and credentials. NBCC engaged forensic investigators, notified the FBI, and provided 12 months of credit monitoring via TransUnion. Notification to residents began January 12, 2021.
Affected (this filing): 880
National Board for Certified Counselors, Inc. (NBCC) disclosed a cybersecurity incident occurring between August 31 and September 7, 2020. An unauthorized actor introduced malware that encrypted files and exfiltrated personal data, including names, addresses, Social Security numbers, dates of birth, and credential information. NBCC engaged third-party forensic investigators, notified the FBI, and offered 12 months of credit monitoring via TransUnion. The incident was discovered on September 7, 2020, and notification letters were issued in 2021.