ENSTAR (US) INC.
bd_1e553d29839a9792 · schema v1 · pii pii-v1
Full breach record for ENSTAR (US) INC. →3 incidents on fileEnstar (US) Inc. disclosed that an unauthorized actor, identified as the criminal group CL0P, exploited a zero-day vulnerability in the MOVEit Transfer tool (provided by Progress Software Corp.) to access its server between May 29 and May 31, 2023. The actor exfiltrated data, including names and other personal information. Enstar launched an investigation with third-party forensic specialists, reported the incident to law enforcement, and is offering 24 months of credit monitoring and identity theft restoration services to affected individuals. The incident was discovered on May 31, 2023, when Progress Software publicly disclosed the vulnerability.
J jump to incidentP pin to compareR raw source
Incident timeline
May 29, 2023
Begins
May 31, 2023
Discovered
May 9, 2024
Filed
vs. sector median
+41 wks slower
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- Vermont State AGCL0Pbd_4ae56d13c234962c2024-05-03 · +6dVerified by operator
- Oregon State AGbd_4fe38683307ff8712024-05-03 · +6dCandidate
- California State AGbd_94388364373ec52a2024-05-03 · +6dVerified by operator
- New Hampshire State AGbd_97f27651f23acbe02024-05-03 · +6dVerified
Show 2 more filings ↓Show fewer ↑up to 8d gap
- Maine State AGbd_d34099feedd0c4722024-05-03 · +6dVerified
- New Hampshire State AGbd_99d688a6c19da6dd2024-05-17 · +8dVerified
Filing propagation · 7 filings · 5 states
View merged incident ↗Pattern: first filing May 3 (VT), last May 17 (NH) — a 14-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.