DisclosureLens
HackingFinancial ServicesTechnologyFinanceVulnerability ExploitCapture Stored DataZero-DaySupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedDownstream VictimsPIIIdentity (basic)Government IDMediumContained

Allianz Global Risks U.S. Insurance Company

bd_99d688a6c19da6dd · schema v1 · pii pii-v1

Severity

Medium

Discovered

Nov 21, 2023

Filed

May 17, 2024

To disclose

25 weeks

Affected

Not disclosed

Linked

7 filings

Confidence

65%
Full breach record for Allianz Global Risks U.S. Insurance Company3 incidents on file

Allianz Global Risks U.S. Insurance Company notified the NH AG of a data breach affecting its third-party vendor, Enstar (US) Inc. Enstar suffered a security incident on May 31, 2023, due to an exploited zero-day vulnerability in MOVEit file transfer software. Unauthorized access occurred May 29-31, 2023, resulting in data exfiltration. Allianz learned of the incident on November 21, 2023, after Enstar notified its administrator, AZRA. Affected data includes PII such as names and government IDs. Enstar provided credit monitoring via Experian.

Incident timeline

undetected · 176 days
discovery → filing · 25 weeks / 178 days

May 29, 2023

Begins

Nov 21, 2023

Discovered

Jan 19, 2024

Scope determined

May 17, 2024

Filed

vs. sector median

+17 wks slower

This filing is one of 7 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (6) · sorted by filing gap

Show 2 more filingsup to 14d gap

Filing propagation · 7 filings · 5 states

View merged incident ↗
Vermont State AGMay 3 · first
Oregon State AGMay 3 · first
California State AGMay 3 · first
Maine State AGMay 3 · first
New Hampshire State AG+14d · this page

Pattern: first filing May 3 (VT), last May 17 (NH) — a 14-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.