ENSTAR (US) INC.
bd_1e553d29839a9792 · schema v1 · pii pii-v1
Full breach record for ENSTAR (US) INC. →Enstar (US) Inc. disclosed that an unauthorized actor, identified as the criminal group CL0P, exploited a zero-day vulnerability in the MOVEit Transfer tool (provided by Progress Software Corp.) to access its server between May 29 and May 31, 2023. The actor exfiltrated data, including names and other personal information. Enstar launched an investigation with third-party forensic specialists, reported the incident to law enforcement, and is offering 24 months of credit monitoring and identity theft restoration services to affected individuals. The incident was discovered on May 31, 2023, when Progress Software publicly disclosed the vulnerability.
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_4fe38683307ff871Oregon State AGfiled 2024-05-03(6d gap)Candidate
- bd_97f27651f23acbe0New Hampshire State AGfiled 2024-05-03(6d gap)Verified
- bd_d34099feedd0c472Maine State AGfiled 2024-05-03(6d gap)Verified
- bd_99d688a6c19da6ddNew Hampshire State AGfiled 2024-05-17(8d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-585119
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 9, 2024
- Raw hash
- 814d8a5bdbf9bed5c7eed7c291719fa8f48e0794a92917146fd58035b8b3d820
Reporting entity
- Name
- Allianz Global Risks U.S. Insurance Companynorm: allianz global risks us insurance
Victim entity
- Name
- ENSTAR (US) INC.norm: enstar us
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Nov 20, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unknown· CL0P
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- CL0PExternal
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 49 weeks(344 days from discovery to filing)
- Compliance flags
- CA 60-day late · 173d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 31, 2023→ Notified: Nov 20, 2023173d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.