HackingData ExfiltratedCustomer Data InvolvedPIIPHIIDENTITY_BASICLowContained
Esha Corporation
bd_baf6c1d85817ed56 · schema v1 · pii pii-v1
Full breach record for Esha Corporation →ESHA, Inc. notified the Idaho Attorney General of a data security incident occurring July 13-17, 2024, discovered July 19, 2024. Unauthorized access resulted in the acquisition of PII and PHI. One Idaho resident was identified. ESHA retained forensic investigators, restored systems, and began mailing notification letters on November 15, 2024, offering credit monitoring.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_04d8ff229989d6a5Vermont State AGfiled 2024-11-15Verified
- bd_8315b50e76f21676New Hampshire State AGfiled 2024-11-15Verified
Source provenance
- Source URL
- https://www.ag.idaho.gov/content/uploads/2024/11/11-15-2024-ESHA-Inc.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 15, 2024
- Raw hash
- 1ec6bca055af782aebb5766b6e1faebaa1b6d1f65b22e7c5b42bab735839b73b
Reporting entity
- Name
- Esha Corporationnorm: esha
Victim entity
- Name
- Esha Corporationnorm: esha
Incident
- Discovered
- Jul 19, 2024
- Materiality determined
- —
- Notification sent
- Nov 15, 2024
- Affected individuals
- 1
- Data types
- PIIPHIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notification of Data Security Incident filed with Idaho Attorney General’s Office
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 17 weeks(119 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.