HackingVulnerability ExploitCL0PZero-DayData ExfiltratedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
ENSTAR (US) INC.
bd_1a017539d064cf59 · schema v1 · pii pii-v1
Full breach record for ENSTAR (US) INC. →Enstar (US) Inc. disclosed a data breach resulting from the exploitation of a zero-day vulnerability in Progress Software's MOVEit Transfer tool by the CL0P criminal group. The incident occurred between May 29 and May 31, 2023. The breach exposed personal information including names and government identifiers. Enstar engaged forensic specialists, notified law enforcement, and offered 24 months of credit monitoring. 103 Rhode Island residents were explicitly identified as affected.
Vermont clock⏱ VT AG >14 bday4 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_2f917e341fd476efMaine State AGfiled 2023-11-20Candidate
- bd_5422ea19f588ed7dNew Hampshire State AGfiled 2023-11-20Verified
- bd_b99b5f8fdd50d888Delaware State AGCL0Pfiled 2023-11-20Verified
- bd_db593da621ce452bMontana State AGfiled 2023-11-20Candidate
Show 4 more filings ↓Show fewer ↑up to 31d gap
- bd_e07251a79e93fcedCalifornia State AGfiled 2023-11-20Candidate
- bd_ed49fa4ae7999ba4Delaware State AGCL0Pfiled 2023-11-20Verified
- bd_71acf5c1b89c92abVermont State AGCL0Pfiled 2023-12-19(29d gap)Verified
- bd_82abb30f43003e62California State AGfiled 2023-12-21(31d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-11-20-enstar-us-progress-software-moveit-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 20, 2023
- Raw hash
- 06d0025602960e76bf9089801771a288e8615f9a57f5d5dbaada12c49cbe8f81
Reporting entity
- Name
- ENSTAR (US) INC.norm: enstar us
Victim entity
- Name
- ENSTAR (US) INC.norm: enstar us
Incident
- Discovered
- Oct 21, 2023
- Materiality determined
- Oct 21, 2023
- Notification sent
- Nov 20, 2023
- Affected individuals
- 103
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access· CL0P
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 ChannelT1486 Data Encrypted for Impact
- Threat actor
- CL0PExternalFinancial
- Regulator citations
- Reported this incident to law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.