MalwareRansomwareData EncryptedData ExfiltratedCustomer Data InvolvedPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
ESO Solutions, Inc.
bd_77f5b20a36fe0209 · schema v1 · pii pii-v1
Full breach record for ESO Solutions, Inc. →ESO Solutions, Inc. experienced a ransomware incident detected on September 28, 2023, with unauthorized access occurring between September 17 and September 28, 2023. An unauthorized third party accessed and encrypted systems, potentially acquiring protected health information (PHI), including names, SSNs, and medical records. ESO engaged forensic specialists, notified the FBI, and offered identity monitoring services to affected individuals.
This filing is one of 11 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_60ee7f54bc74b1a8Washington State AGfiled 2023-12-20Candidate
- bd_60f651f710cadc8aWashington State AGfiled 2023-12-20Candidate
- bd_90976a3a172cf7ffOregon State AGfiled 2023-12-20Candidate
- bd_343e59873d00e6e1California State AGfiled 2023-12-19(1d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 8d gap
- bd_3d4d0c8f649cc17cMaine State AGfiled 2023-12-19(1d gap)Verified
- bd_ce0ffcf6780e06cdMontana State AGfiled 2023-12-19(1d gap)Verified
- bd_6112512cced570f4HHS OCRfiled 2023-12-18(2d gap)Candidate
- bd_8644267b7660eed4New Hampshire State AGfiled 2023-12-26(6d gap)Verified
- bd_b9df81e7956c2d0dDelaware State AGfiled 2023-12-12(8d gap)Candidate
- bd_e7f72c12079cffd2Vermont State AGfiled 2023-12-12(8d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-578243
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 20, 2023
- Raw hash
- 4fe0be87e2aecefe7dba7094943deedfb541efc6ab882b1dc53fb6d0b7e3c30e
Reporting entity
- Name
- ESO Solutions, Inc.norm: eso solutions
Victim entity
- Name
- ESO Solutions, Inc.norm: eso solutions
Incident
- Discovered
- Sep 28, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified the FBI (Federal Bureau of Investigation)
Compliance
- Time to disclose
- 12 weeks(83 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.