HackingVulnerability ExploitCL0PZero-DayData ExfiltratedTargetedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
ENSTAR (US) INC.
bd_b99b5f8fdd50d888 · schema v1 · pii pii-v1
Full breach record for ENSTAR (US) INC. →Enstar (US) Inc. notified individuals of a data breach involving the MOVEit Transfer zero-day vulnerability exploited by the CL0P criminal group. Unauthorized access occurred between May 29 and May 31, 2023, resulting in data exfiltration. The breach affected individuals across multiple jurisdictions, including 103 Rhode Island residents. Enstar engaged forensic specialists, reported to law enforcement, and offered 24 months of credit monitoring.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_1a017539d064cf59Vermont State AGCL0Pfiled 2023-11-20Verified
- bd_2f917e341fd476efMaine State AGfiled 2023-11-20Candidate
- bd_5422ea19f588ed7dNew Hampshire State AGfiled 2023-11-20Verified
- bd_db593da621ce452bMontana State AGfiled 2023-11-20Candidate
Show 4 more filings ↓Show fewer ↑up to 31d gap
- bd_e07251a79e93fcedCalifornia State AGfiled 2023-11-20Candidate
- bd_ed49fa4ae7999ba4Delaware State AGCL0Pfiled 2023-11-20Verified
- bd_71acf5c1b89c92abVermont State AGCL0Pfiled 2023-12-19(29d gap)Verified
- bd_82abb30f43003e62California State AGfiled 2023-12-21(31d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/11/Enstar-Individual-Notice-Template.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 20, 2023
- Raw hash
- 413baadc75c78a9cc08aa73bb2f5085d90c7bb4a0d2d02255e335154f24cbd58
Reporting entity
- Name
- ENSTAR (US) INC.norm: enstar us
Victim entity
- Name
- ENSTAR (US) INC.norm: enstar us
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Nov 20, 2023
- Affected individuals
- 103
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access· CL0P
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 ChannelT1486 Data Encrypted for Impact
- Threat actor
- CL0PExternalFinancial
- Regulator citations
- reported this incident to law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 25 weeks(173 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.