MalwareRansomwareData EncryptedData ExfiltratedCustomer Data InvolvedPHIIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICMediumContained
ESO Solutions, Inc.
bd_343e59873d00e6e1 · schema v1 · pii pii-v1
Full breach record for ESO Solutions, Inc. →ESO Solutions, Inc. experienced a ransomware incident on September 17, 2023, detected on September 28, 2023. An unauthorized third party accessed and encrypted systems, potentially acquiring protected health information (PHI), including SSNs, medical records, and insurance data for patients and minors. ESO engaged forensic experts, notified the FBI, and offered identity monitoring.
This filing is one of 11 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_3d4d0c8f649cc17cMaine State AGfiled 2023-12-19Verified
- bd_ce0ffcf6780e06cdMontana State AGfiled 2023-12-19Verified
- bd_60ee7f54bc74b1a8Washington State AGfiled 2023-12-20(1d gap)Candidate
- bd_60f651f710cadc8aWashington State AGfiled 2023-12-20(1d gap)Candidate
Show 6 more filings ↓Show fewer ↑up to 7d gap
- bd_77f5b20a36fe0209California State AGfiled 2023-12-20(1d gap)Verified
- bd_90976a3a172cf7ffOregon State AGfiled 2023-12-20(1d gap)Candidate
- bd_6112512cced570f4HHS OCRfiled 2023-12-18(1d gap)Candidate
- bd_8644267b7660eed4New Hampshire State AGfiled 2023-12-26(7d gap)Verified
- bd_b9df81e7956c2d0dDelaware State AGfiled 2023-12-12(7d gap)Candidate
- bd_e7f72c12079cffd2Vermont State AGfiled 2023-12-12(7d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-578125
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 19, 2023
- Raw hash
- 0abba12d3a2eabf9354f56a6ba244e018bfb7d082a56849b2a2a13206f0eb6ff
Reporting entity
- Name
- ESO Solutions, Inc.norm: eso solutions
Victim entity
- Name
- ESO Solutions, Inc.norm: eso solutions
Incident
- Discovered
- Sep 28, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified the FBI (Federal Bureau of Investigation)
Compliance
- Time to disclose
- 12 weeks(82 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.