HackingVulnerability ExploitCL0PZero-DayData ExfiltratedTargetedIDENTITY_BASICLowContained
ENSTAR (US) INC.
bd_71acf5c1b89c92ab · schema v1 · pii pii-v1
Full breach record for ENSTAR (US) INC. →Enstar (US) Inc. notified consumers of a data breach involving its MOVEit Transfer server. The criminal group CL0P exploited a zero-day vulnerability (May 29-31, 2023) to exfiltrate data. Affected data included names and other elements. Enstar engaged forensic specialists, reported to law enforcement, and offered 24 months of credit monitoring. Rhode Island residents were explicitly identified as impacted.
Vermont clock✗ VT AG >45 bday29 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_82abb30f43003e62California State AGfiled 2023-12-21(2d gap)Verified
- bd_1a017539d064cf59Vermont State AGCL0Pfiled 2023-11-20(29d gap)Verified
- bd_2f917e341fd476efMaine State AGfiled 2023-11-20(29d gap)Candidate
- bd_5422ea19f588ed7dNew Hampshire State AGfiled 2023-11-20(29d gap)Verified
Show 4 more filings ↓Show fewer ↑up to 29d gap
- bd_b99b5f8fdd50d888Delaware State AGCL0Pfiled 2023-11-20(29d gap)Verified
- bd_db593da621ce452bMontana State AGfiled 2023-11-20(29d gap)Candidate
- bd_e07251a79e93fcedCalifornia State AGfiled 2023-11-20(29d gap)Candidate
- bd_ed49fa4ae7999ba4Delaware State AGCL0Pfiled 2023-11-20(29d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-12-19-enstar-group-limited-progress-software-moveit-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 19, 2023
- Raw hash
- 145592d605318ef36933c58335e488b8144d9d115a310371f5759aacb57ceeaa
Reporting entity
- Name
- Enstar Groupnorm: enstar group
- Domain
- enstargroup.com
Victim entity
- Name
- ENSTAR (US) INC.norm: enstar us
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Nov 20, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- CL0PExternalFinancial
- Regulator citations
- reported this incident to law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 29 weeks(202 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.