ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Healthcare software company NASCO adds 1.6m people to its list of MOVEit breach victims

Atlanta, Georgia-based healthcare software company NASCO says the MOVEit Transfer breach it suffered last year impacted 1.6 million more people than initially believed.In its first data breach notification filed with the Office of the Maine Attorney General in October, NASCO said that it used Progress Software’s MOVEit Transfer web application to send and receive files securely and was impacted after cyber criminals exploited a zero-day vulnerability in the application.After being notified by Progress Software, the manufacturer of MOVEit software, NASCO immediately launched an internal investigation with assistance from third party cyber security experts to understand the scope of the incident.The investigation revealed that the sensitive personal information of its patients, including their health plan details, was accessed by the threat actors. The compromised information also included the names and other personal identifiers, such as social security numbers of patients.NASCO said in its filing with the Attorney General’s Office that at least 804,862 individuals were impacted as a result of the incident. However, in a recent filing with the regulator, NASCO said that it has identified another 1,696,867 individuals who were affected by the data security incident.“We take the protection of your personal information seriously as data privacy and security are among our highest priorities, and we have extensive measures in place to protect information entrusted to us,” NASCO said.“Upon discovering the incident, we promptly took steps to mitigate the risk to our customers and personal information. The NASCO MOVEit server affected by the attack was decommissioned and is no longer accessible from the internet. MOVEit is no longer used by NASCO.“Forensic evidence showed no threat actor activity outside of the MOVEit vulnerability exploitation. NASCO continues to work with law enforcement on this issue,” the company added.To prevent similar security incidents from happening in the future, the healthcare software company has implemented additional procedures to further strengthen the security of its IT system environment and has urged all affected people to remain vigilant against incidents of identity theft and fraud.NASCO said it is providing two years of complimentary credit monitoring, identity theft resolution services, and $1,000,000 of identity theft insurance through Experian to all the individuals affected by the data breach.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543