North Country Business Products (NCBP), a US-based technology company, was targeted in a ransomware attack by the handala group on March 28, 2026. The incident resulted in the disabling of 2,680 Point of Sale (POS) terminals across the country. NCBP provides POS systems to various retail chains, making this potentially a vendor breach affecting their downstream customers.
While the breach impacted systems nationwide, no specific states have been identified. As of March 31, 2026, there is no public information confirming the exposure of personal data such as SSNs, medical records, or financial information. The focus of initial reports is on operational disruption rather than data exfiltration. No class action lawsuits, attorney general filings, or official breach notification letters have been reported.
Details can emerge later as investigations continue, and notices may be delayed.