Full Report
A data breach involving NCH was reported in May 2026. See incident details, impact on customers, and recommended security measures.
Analysis Summary
# Incident Report: NCH Corporation Data Breach (May 2026)
## Executive Summary
NCH Corporation experienced a sustained unauthorized network intrusion between January and February 2026, resulting in the exfiltration of sensitive employee and customer files. The breach compromised highly sensitive personal identifiers, including Social Security numbers and benefits enrollment data. NCH has since engaged in state-mandated notifications and offered identity monitoring services to mitigate the risk of identity theft.
## Incident Details
- **Discovery Date:** April 2, 2026
- **Incident Date:** January 21, 2026 – February 25, 2026
- **Affected Organization:** NCH Corporation (nch[.]com)
- **Sector:** Industrial/Commercial Services
- **Geography:** United States (Headquartered in Irving, Texas; Maine residents specifically noted)
## Timeline of Events
### Initial Access
- **Date/Time:** January 21, 2026
- **Vector:** Unknown unauthorized third-party intrusion.
- **Details:** An unidentified threat actor gained access to NCH’s internal network, maintaining presence for approximately five weeks.
### Lateral Movement
- **Details:** The attacker navigated through internal systems to access file directories containing Human Resources and benefits information. Specific lateral movement techniques (e.g., RDP, SMB) were not disclosed in the public report.
### Data Exfiltration/Impact
- **Date/Time:** Between Jan 21 and Feb 25, 2026.
- **Details:** Files were exfiltrated containing sensitive PII (Personally Identifiable Information) including full names, SSNs, and benefits data.
### Detection & Response
- **Discovery:** April 2, 2026 (Internal discovery by NCH).
- **Response Actions:** Investigation launched to determine scope; legal notifications sent to state regulators (Maine) and affected individuals starting May 1, 2026.
## Attack Methodology
- **Initial Access:** Unauthorized third-party intrusion (Specific vector undisclosed).
- **Persistence:** Sustained presence in the network for 35 days.
- **Privilege Escalation:** Undisclosed; however, access to sensitive benefits enrollment files suggests elevated permissions were obtained.
- **Defense Evasion:** Undisclosed; the actor remained undetected for over two months.
- **Credential Access:** Undisclosed.
- **Discovery:** Reconnaissance of internal file servers containing PII.
- **Lateral Movement:** Undisclosed.
- **Collection:** Gathering of files containing names, DOBs, and SSNs.
- **Exfiltration:** Transfer of sensitive files to an external location.
- **Impact:** Medium severity; high risk of long-term identity theft and fraud.
## Impact Assessment
- **Financial:** Potential for significant costs related to identity monitoring services (provided through IDX), legal fees, and regulatory fines.
- **Data Breach:** Compromise of full names, Social Security numbers, dates of birth, and benefits enrollment information.
- **Operational:** Diversion of IT and legal resources to incident response and remediation.
- **Reputational:** Public disclosure of the breach may impact stakeholder trust; residents of Maine and other states officially notified.
## Indicators of Compromise
- **Network indicators:** None disclosed (Recommended to monitor for unauthorized outbound connections to unknown IPs).
- **File indicators:** None disclosed.
- **Behavioral indicators:** Unusual access to benefits and HR file shares outside of normal business hours or from unusual accounts.
## Response Actions
- **Containment:** Secured internal systems following discovery on April 2.
- **Eradication:** Undisclosed, presumably involved removal of unauthorized access points.
- **Recovery:** NCH is providing one year of complimentary identity monitoring through IDX to all affected individuals.
## Lessons Learned
- **Detection Lag:** The time between initial access (Jan 21) and discovery (April 2) indicates a significant gap in real-time threat detection and monitoring.
- **Data Sensitivity:** The storage of unencrypted or accessible SSNs and benefits data in areas reachable via network intrusion facilitated the high-impact exfiltration.
## Recommendations
- **Identity Security:** Implement phishing-resistant Multi-Factor Authentication (MFA) across all corporate and external-facing accounts.
- **Data Protection:** Encrypt sensitive PII at rest, specifically files containing Social Security numbers and benefits data.
- **Monitoring:** Implement automated Attack Surface Management and continuous network monitoring to detect unauthorized intrusions faster than the 71-day detection window observed here.
- **Consumer Defense:** Affected individuals should place a security freeze on credit reports with Equifax, Experian, and TransUnion.