HackingVulnerability ExploitCL0PZero-DayData ExfiltratedCustomer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
ENSTAR (US) INC.
bd_ed49fa4ae7999ba4 · schema v1 · pii pii-v1
Full breach record for ENSTAR (US) INC. →Enstar (US) Inc. notified Rhode Island residents of a data breach involving the MOVEit Transfer tool. The criminal group CL0P exploited a zero-day vulnerability to access the server between May 29 and May 31, 2023, and exfiltrated data. The breach affected 103 Rhode Island residents, exposing names and government identifiers. Enstar reported the incident to law enforcement, engaged forensic specialists, and offered 24 months of credit monitoring.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_1a017539d064cf59Vermont State AGCL0Pfiled 2023-11-20Verified
- bd_2f917e341fd476efMaine State AGfiled 2023-11-20Candidate
- bd_5422ea19f588ed7dNew Hampshire State AGfiled 2023-11-20Verified
- bd_b99b5f8fdd50d888Delaware State AGCL0Pfiled 2023-11-20Verified
Show 4 more filings ↓Show fewer ↑up to 31d gap
- bd_db593da621ce452bMontana State AGfiled 2023-11-20Candidate
- bd_e07251a79e93fcedCalifornia State AGfiled 2023-11-20Candidate
- bd_71acf5c1b89c92abVermont State AGCL0Pfiled 2023-12-19(29d gap)Verified
- bd_82abb30f43003e62California State AGfiled 2023-12-21(31d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/11/Enstar-Individual-Notice-Template.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 20, 2023
- Raw hash
- e0a6e5ed25481548318dbedc2957c17204c88f6d8dedb70a1a3c3ccc71f3ff8b
Reporting entity
- Name
- ENSTAR (US) INC.norm: enstar us
Victim entity
- Name
- ENSTAR (US) INC.norm: enstar us
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Nov 20, 2023
- Affected individuals
- 103
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access· CL0P
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- CL0PExternalFinancial
- Regulator citations
- reported this incident to law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 25 weeks(173 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.