CSIDB logo
Incident

NCH Corporation

Incident posture

Attack window
Jan 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-17 13:02

Linked entities

Victim
NCH Corporation
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Jan 2026
Discovered
Mar 2026
Disclosed
May 2026
Resolved
Pending

Summary

NCH Corporation experienced a data breach after discovering that an unauthorized actor had accessed its network and copied files containing personal information. The subsequent investigation revealed that the intrusion occurred over a span of several weeks, during which data such as names, taxpayer identification numbers, driver’s license or state‑issued identification numbers, passport numbers, other government‑issued identifiers, financial account details, payment card information, medical data, and health insurance information may have been exposed. A national class‑action law firm has opened an investigation into the incident to assess potential claims for affected individuals.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

NCH Corporation, a global manufacturer and marketer of industrial maintenance, water treatment, and lubrication solutions headquartered in Irving, Texas, discovered on March 9, 2026 that an unauthorized actor had taken files from its network. Upon discovery, the company initiated response procedures and engaged third‑party cybersecurity professionals to conduct an investigation. The investigation confirmed that unauthorized activity had occurred within NCH’s network between January 21, 2026 and February 25, 2026. During that window the intruder obtained copies of certain files containing personal data. The compromised information may include names combined with taxpayer identification numbers, driver’s license or state‑issued identification card numbers, passport numbers, other government‑issued identification numbers, financial account information, payment card information, medical information, or health insurance information.

As part of its response, NCH Corporation notified individuals whose data may have been affected and informed them of the potential increase in risk for identity theft and fraud. The company’s investigation, supported by external experts, aimed to determine the full scope of the accessed files and to secure the network against further unauthorized access. Edelson Lechtzin LLP, a national class action law firm with offices in Pennsylvania and California, announced on May 3, 2026 that it is investigating a putative class action related to the incident. The firm stated that it is offering free case evaluations to individuals who believe their sensitive data may have been compromised.

The law firm’s announcement included contact information for Marc Edelson, Esq., at 411 S. State Street, Suite N‑300, Newtown, PA 18940, phone 844‑696‑7492 ext. 2, and email medelson@edelson‑law.com. It also referenced the firm’s website page dedicated to data‑breach class actions. Edelson Lechtzin LLP noted that, beyond data‑breach litigation, its practice covers securities and investment fraud, federal antitrust, ERISA, wage theft, and consumer protection matters.

In its compliance and verification notice, the law firm emphasized that it has not independently verified the full scope, contents, or authenticity of the alleged data, and that references to data volume, record counts, and categories are based on third‑party reports and remain subject to confirmation. It added that preliminary findings about the nature and sensitivity of the information are still under review and are not conclusive, and that nothing in the announcement should be interpreted as a definitive finding regarding liability, causation, or the precise impact of the incident.

Sources

Sources available to members: 2 sources.

CSIDB