HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Enterprise Financial Group, Inc.
bd_375db7cc9864f98d · schema v1 · pii pii-v1
Full breach record for Enterprise Financial Group, Inc. →Enterprise Financial Group Inc. disclosed a security incident on February 18, 2024, where an unauthorized third party accessed and copied files from its internal network. The breach was caused by unknown vulnerabilities in a third-party VPN appliance. The investigation confirmed that personal information, including Social Security Numbers and bank account numbers, was involved. The company engaged external cybersecurity experts, patched the vulnerability, replaced the VPN appliance, and offered credit monitoring services to affected individuals.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_40a3832a6618a1c1Indiana State AGfiled 2024-08-14Candidate
- bd_e651d689fdb81d5bMaine State AGfiled 2024-08-14Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/enterprise-financial-group-20240814.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 14, 2024
- Raw hash
- df83b8e97929f91bde82b04e12b27ef3763ff39e4742a234b2e2c3769de1f95b
Reporting entity
- Name
- Enterprise Financial Group, Inc.norm: enterprise financial
Victim entity
- Name
- Enterprise Financial Group, Inc.norm: enterprise financial
Incident
- Discovered
- Feb 18, 2024
- Materiality determined
- Jul 15, 2024
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 25 weeks(178 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.