HackingVulnerability ExploitCapture Stored DataZero-DaySupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedDownstream VictimsPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
ENSTAR (US) INC.
bd_99d688a6c19da6dd · schema v1 · pii pii-v1
Full breach record for ENSTAR (US) INC. →Allianz Global Risks U.S. Insurance Company notified the NH AG of a data breach affecting its third-party vendor, Enstar (US) Inc. Enstar suffered a security incident on May 31, 2023, due to an exploited zero-day vulnerability in MOVEit file transfer software. Unauthorized access occurred May 29-31, 2023, resulting in data exfiltration. Allianz learned of the incident on November 21, 2023, after Enstar notified its administrator, AZRA. Affected data includes PII such as names and government IDs. Enstar provided credit monitoring via Experian.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_1e553d29839a9792California State AGCL0Pfiled 2024-05-09(8d gap)Verified by operator
- bd_4fe38683307ff871Oregon State AGfiled 2024-05-03(14d gap)Candidate
- bd_97f27651f23acbe0New Hampshire State AGfiled 2024-05-03(14d gap)Verified
- bd_d34099feedd0c472Maine State AGfiled 2024-05-03(14d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/allianz-global-risks-us-insurance-20240517.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 17, 2024
- Raw hash
- fac624085aa1d780e5d01f4b0bb747b5cd8dfbf64acbd852039cb6d3b0eb7e8b
Reporting entity
- Name
- Allianz Global Risks U.S. Insurance Companynorm: allianz global risks us insurance
Victim entity
- Name
- ENSTAR (US) INC.norm: enstar us
Incident
- Discovered
- Nov 21, 2023
- Materiality determined
- Jan 19, 2024
- Notification sent
- Nov 20, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 ChannelT1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General Consumer Protection Bureau
- Third party
- via Enstar (US) Inc.
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 25 weeks(178 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.