Company Details
nch
5,232
60,732
325
nch.com
0
NCH_4334465
In-progress

NCH Corporation Company CyberSecurity Posture
nch.comCleaning water, conserving energy and delivering maintenance solutions since 1919. We clean and conserve water, save energy, and deliver best-in-class maintenance solutions, with a focus on industrial and commercial businesses. NCH has over 7,500 employees, with branch offices and manufacturing plants located on six continents. We distribute to more than 50 countries with an extensive and varied product line, and our outlook for growth in the market remains strong. Leadership of the company remains in the hands of the Levy family, descendants of the founding father, Milton P. Levy, Senior. NCH sells to industrial, commercial, institutional and retail customers. We focus on product areas including: - Industrial cleaning and maintenance - Water treatment and remediation - Plumbing Subsidiaries in NCH's Chemical divisions produce wastewater treatment products, drain cleaners, degreasers, lubricants, grounds care, fuel and water treatment programs and a variety of other biological solutions for industrial and commercial applications. The Plumbing Products Group provides supplies for the DIY consumer and the OEM market. NCH's strengths are the diversity and quality of our products and the organization of direct sales representatives. We choose acquisitions carefully and invest wisely in manufacturing and research facilities, a crucial commitment given to the competition in the industrial supply business. To date, we are the strongest and largest leading private global provider of industrial maintenance solutions in the world. Career Page: https://careers.nch.com Website: www.nch.com
Company Details
nch
5,232
60,732
325
nch.com
0
NCH_4334465
In-progress
Between 650 and 699

NCH Corporation Global Score (TPRM)XXXX

Description: The Maine Attorney General's Office reported that NCH Corporation experienced a data breach involving unauthorized access to its network between March 2, 2021, and March 5, 2021. The breach potentially exposed the names and Social Security numbers and/or drivers’ license numbers of certain current and former employees and their dependents. NCH plans to notify six affected Maine residents by mail starting July 29, 2021.
Description: Recently, NCH announced that it had experienced a data breach in which sensitive personal identifiable information in its care may have been compromised. According to the breach notice shared on its website, NCH became aware that an unauthorized actor leveraged a previously unknown vulnerability in Oracle’s E-Business Suite (“Oracle EBS”), which NCH uses to manage operations, to take information from numerous organizations’ Oracle EBS applications.1 As a result, NCH launched an investigation to determine the nature of the incident. Through its investigation, NCH confirmed that sensitive personal information in its Oracle EBS application may have been accessed and acquired by an unauthorized third party in mid-August. As a result, NCH began a review of the data to determine what information had been impacted as well as identify the specific individuals affected. While the information impacted varies depending on the individual, the type of information potentially exposed includes: Name Social Security number Date of birth Benefits election information As a result of the breach, NCH posted notice of the breach on its website. Additionally, on December 5, 2025, NCH began mailing data breach notification letters to impacted individuals. Based on the breach notice sent to Maine residents, NCH is providing affected individuals with a list of the specific types of sensitive information impacted and 12 months of complimentary credit monitoring services. A link to the website br


NCH Corporation has 0.0% fewer incidents than the average of same-industry companies with at least one recorded incident.
NCH Corporation has 53.85% more incidents than the average of all companies with at least one recorded incident.
NCH Corporation reported 1 incidents this year: 0 cyber attacks, 0 ransomware, 0 vulnerabilities, 1 data breaches, compared to industry peers with at least 1 incident.
NCH Corporation cyber incidents detection timeline including parent company and subsidiaries

Cleaning water, conserving energy and delivering maintenance solutions since 1919. We clean and conserve water, save energy, and deliver best-in-class maintenance solutions, with a focus on industrial and commercial businesses. NCH has over 7,500 employees, with branch offices and manufacturing plants located on six continents. We distribute to more than 50 countries with an extensive and varied product line, and our outlook for growth in the market remains strong. Leadership of the company remains in the hands of the Levy family, descendants of the founding father, Milton P. Levy, Senior. NCH sells to industrial, commercial, institutional and retail customers. We focus on product areas including: - Industrial cleaning and maintenance - Water treatment and remediation - Plumbing Subsidiaries in NCH's Chemical divisions produce wastewater treatment products, drain cleaners, degreasers, lubricants, grounds care, fuel and water treatment programs and a variety of other biological solutions for industrial and commercial applications. The Plumbing Products Group provides supplies for the DIY consumer and the OEM market. NCH's strengths are the diversity and quality of our products and the organization of direct sales representatives. We choose acquisitions carefully and invest wisely in manufacturing and research facilities, a crucial commitment given to the competition in the industrial supply business. To date, we are the strongest and largest leading private global provider of industrial maintenance solutions in the world. Career Page: https://careers.nch.com Website: www.nch.com

Welcome to Solvay, where science and mastery come together, creating excellence that stands the test of time. With a 160-year legacy, we're not just innovators; we're on a constant journey of progress, mastering the essential elements of our world. We're all about revealing potentials, just like

We are dsm-firmenich – innovators in nutrition, health, and beauty. We bring progress to life by combining the essential, the desirable, and the sustainable. From our master perfumers and flavorists to our expert nutritionists and scientists, our trailblazing teams work closely with customers, sup

SABIC is a global leader in chemicals headquartered in Riyadh, Saudi Arabia. From making cars and planes more fuel-efficient, to helping conserve the world’s water supply and enabling colorful smartphone cases, we find solutions to the challenges of today to help our customers achieve their ambition

Meet IFF: We boldly bring together science and creativity to create what the world needs. An industry leader in food, beverage, scent, health and biosciences, we create essential solutions – from global icons to unexpected innovations and experiences. Equal parts outspoken and analytical, our inte

Founded in 1920, Eastman is a global specialty materials company that produces a broad range of products found in items people use every day. With the purpose of enhancing the quality of life in a material way, Eastman works with customers to deliver innovative products and solutions while maintaini

Bayer is a global enterprise with core competencies in the life science fields of healthcare and nutrition. We design our products and services to serve the most essential human needs of health and nutrition. At the same time, we strive to address some of the world’s biggest challenges presented by

Since 1792, we’ve been supplying the innovative paints and coatings that help to color people’s lives and protect what matters most. Our world class portfolio of brands – including Dulux, International, Sikkens and Interpon – is trusted by customers around the globe. We’re active in more than 150 co

Sika is a specialty chemicals company with a globally leading position in the development and production of systems and products for bonding, sealing, damping, reinforcing, and protection in the building sector and industrial manufacturing. Sika has subsidiaries in 102 countries around the world and
Evonik is one of the world’s leading specialty chemicals companies. While we don’t produce electric cars, aircraft, medications or 3D printers, Evonik is part and parcel of these and many other end products. That’s because we contribute the small things that make a big difference. We make electric c
.png)
Ruli AI, a AI-native legal intelligence platform for in-house legal teams, raised $6M in a round led by Album VC with participation from...
With the acquisition, Solenis has grown into an enterprise operating in over 160 countries with approximately 23000 employees.
The combined company will unite complementary business models to further solidify Solenis' position as a global leader for water and hygiene...
Tech industry leader Gertrude 'Trude' Van Horn is poised to be inducted into the distinguished Tech Titans Hall of Fame.
This year's list of honorees includes technology executives that span across industries—from real estate to restaurants to healthcare.

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of NCH Corporation is http://www.nch.com/.
According to Rankiteo, NCH Corporation’s AI-generated cybersecurity score is 684, reflecting their Weak security posture.
According to Rankiteo, NCH Corporation currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, NCH Corporation is not certified under SOC 2 Type 1.
According to Rankiteo, NCH Corporation does not hold a SOC 2 Type 2 certification.
According to Rankiteo, NCH Corporation is not listed as GDPR compliant.
According to Rankiteo, NCH Corporation does not currently maintain PCI DSS compliance.
According to Rankiteo, NCH Corporation is not compliant with HIPAA regulations.
According to Rankiteo,NCH Corporation is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
NCH Corporation operates primarily in the Chemical Manufacturing industry.
NCH Corporation employs approximately 5,232 people worldwide.
NCH Corporation presently has no subsidiaries across any sectors.
NCH Corporation’s official LinkedIn profile has approximately 60,732 followers.
NCH Corporation is classified under the NAICS code 325, which corresponds to Chemical Manufacturing.
No, NCH Corporation does not have a profile on Crunchbase.
Yes, NCH Corporation maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/nch.
As of December 10, 2025, Rankiteo reports that NCH Corporation has experienced 2 cybersecurity incidents.
NCH Corporation has an estimated 4,200 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Breach.
Detection and Response: The company detects and responds to cybersecurity incidents through an communication strategy with notification by mail to affected individuals, and incident response plan activated with yes, and communication strategy with posted notice on website and mailed data breach notification letters..
Title: NCH Corporation Data Breach
Description: Unauthorized access to NCH Corporation's network potentially exposed names and Social Security numbers and/or drivers’ license numbers of certain current and former employees and their dependents.
Date Detected: 2021-03-05
Date Publicly Disclosed: 2021-07-29
Type: Data Breach
Attack Vector: Unauthorized Access
Title: NCH Data Breach via Oracle E-Business Suite Vulnerability
Description: NCH experienced a data breach where sensitive personal identifiable information may have been compromised due to an unauthorized actor exploiting a previously unknown vulnerability in Oracle’s E-Business Suite (Oracle EBS). The breach affected numerous organizations using Oracle EBS, and NCH confirmed that personal data was accessed and acquired by an unauthorized third party in mid-August.
Date Detected: 2025-08-15
Date Publicly Disclosed: 2025-12-05
Type: Data Breach
Attack Vector: Exploitation of unknown vulnerability
Vulnerability Exploited: Previously unknown vulnerability in Oracle E-Business Suite
Threat Actor: Unauthorized third party
Common Attack Types: The most common types of attacks the company has faced is Breach.
Identification of Attack Vectors: The company identifies the attack vectors used in incidents through Oracle E-Business Suite vulnerability.

Data Compromised: Names, Social security numbers, Drivers’ license numbers

Data Compromised: Sensitive personal identifiable information
Systems Affected: Oracle E-Business Suite
Identity Theft Risk: High
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Names, Social Security Numbers, Drivers’ License Numbers, , Name, Social Security Number, Date Of Birth, Benefits Election Information and .

Entity Name: NCH
Entity Type: Organization
Industry: Healthcare
Customers Affected: Numerous individuals

Communication Strategy: Notification by mail to affected individuals

Incident Response Plan Activated: Yes
Communication Strategy: Posted notice on website and mailed data breach notification letters
Incident Response Plan: The company's incident response plan is described as Yes.

Type of Data Compromised: Names, Social security numbers, Drivers’ license numbers
Sensitivity of Data: High

Type of Data Compromised: Name, Social security number, Date of birth, Benefits election information
Sensitivity of Data: High
Data Exfiltration: Yes
Personally Identifiable Information: Yes

Source: NCH Breach Notice
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Maine Attorney General's OfficeDate Accessed: 2021-07-29, and Source: NCH Breach Notice.

Investigation Status: Completed
Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Notification by mail to affected individuals and Posted notice on website and mailed data breach notification letters.

Customer Advisories: 12 months of complimentary credit monitoring services provided to affected individuals
Advisories Provided: The company provides the following advisories to stakeholders and customers following an incident: was 12 months of complimentary credit monitoring services provided to affected individuals.

Entry Point: Oracle E-Business Suite vulnerability

Root Causes: Exploitation of unknown vulnerability in Oracle E-Business Suite
Last Attacking Group: The attacking group in the last incident was an Unauthorized third party.
Most Recent Incident Detected: The most recent incident detected was on 2021-03-05.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2025-12-05.
Most Significant Data Compromised: The most significant data compromised in an incident were Names, Social Security numbers, Drivers’ license numbers, and Sensitive personal identifiable information.
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Social Security numbers, Drivers’ license numbers, Sensitive personal identifiable information and Names.
Most Recent Source: The most recent source of information about an incident are NCH Breach Notice and Maine Attorney General's Office.
Current Status of Most Recent Investigation: The current status of the most recent investigation is Completed.
Most Recent Customer Advisory: The most recent customer advisory issued was an 12 months of complimentary credit monitoring services provided to affected individuals.
Most Recent Entry Point: The most recent entry point used by an initial access broker was an Oracle E-Business Suite vulnerability.
.png)
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Versions 3.5.4 and below contain a Stored Cross-Site Scripting (XSS) vulnerability in the /WeGIA/html/geral/configurar_senhas.php endpoint. The application does not sanitize user-controlled data before rendering it inside the employee selection dropdown. The application retrieves employee names from the database and injects them directly into HTML <option> elements without proper escaping. This issue is fixed in version 3.5.5.
ZITADEL is an open-source identity infrastructure tool. Versions 4.0.0-rc.1 through 4.7.0 are vulnerable to DOM-Based XSS through the Zitadel V2 logout endpoint. The /logout endpoint insecurely routes to a value that is supplied in the post_logout_redirect GET parameter. As a result, unauthenticated remote attacker can execute malicious JS code on Zitadel users’ browsers. To carry out an attack, multiple user sessions need to be active in the same browser, however, account takeover is mitigated when using Multi-Factor Authentication (MFA) or Passwordless authentication. This issue is fixed in version 4.7.1.
ZITADEL is an open-source identity infrastructure tool. Versions 4.7.0 and below are vulnerable to an unauthenticated, full-read SSRF vulnerability. The ZITADEL Login UI (V2) treats the x-zitadel-forward-host header as a trusted fallback for all deployments, including self-hosted instances. This allows an unauthenticated attacker to force the server to make HTTP requests to arbitrary domains, such as internal addresses, and read the responses, enabling data exfiltration and bypassing network-segmentation controls. This issue is fixed in version 4.7.1.
NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are vulnerable to directory traversal through the App.add_media_files() function, which allows a remote attacker to read arbitrary files on the server filesystem. This issue is fixed in version 3.4.0.
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the authentication type is set to "webserver." When providing an Authorization header with an arbitrary value, a session is associated with the target user regardless of valid credentials. This issue is fixed in versions 16.0.44 and 17.0.23.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.