ENSTAR (US) INC.
ent_019e6184870761bfd61a5419a19cebb5
Disclosures
17
State AG · 10 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
75,101
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- ENSTAR (US) INC.
- Normalized
- enstar us— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 213800E7ORRBX5IBFL07
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
- Corporate parent
- Enstar Group— per GLEIF relationship records
Disclosure history (17)newest first
- California State AGas victim2024-05-09
Enstar (US) Inc. disclosed that an unauthorized actor, identified as the criminal group CL0P, exploited a zero-day vulnerability in the MOVEit Transfer tool (provided by Progress Software Corp.) to access its server between May 29 and May 31, 2023. The actor exfiltrated data, including names and other personal information. Enstar launched an investigation with third-party forensic specialists, reported the incident to law enforcement, and is offering 24 months of credit monitoring and identity theft restoration services to affected individuals. The incident was discovered on May 31, 2023, when Progress Software publicly disclosed the vulnerability.
- Vermont State AGas victim2024-05-03
Enstar (US) Inc. notified Vermont AG of a data breach involving the MOVEit Transfer zero-day vulnerability exploited by the CL0P criminal group. The incident occurred May 29-31, 2023. Enstar engaged forensic specialists, notified law enforcement, and offered 24 months of credit monitoring. Data accessed included names and other elements.
- Oregon State AGas victim2024-05-03
Enstar (US), Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2024-05-03. The breach occurred during 5/30/2023 - 5/31/2023. The breach was discovered on 10/21/2023. 75,101 individuals were affected. Notice was sent on 11/20/202312/19/20235/3/2024.
- California State AGas victim2024-05-03
Enstar (US) Inc filed a supplemental data breach notification with the California Attorney General. The incident occurred between May 30 and May 31, 2023. The notice offers 24 months of credit monitoring via Experian. Specific data types and affected counts are not detailed in the provided excerpts, though identity and financial data are implied by the remediation offer. The filing covers residents of multiple states including CA, RI, DC, MD, NM, NY, and NC.
- New Hampshire State AGas victim2024-05-03
Enstar US Inc. filed a supplemental notice with the New Hampshire Attorney General regarding a data event affecting individuals in multiple states. The incident, occurring in June 2023, involved unauthorized access to personal information including names, addresses, and Social Security numbers. Enstar notified the FBI, offered 24 months of credit monitoring via Experian, and implemented additional security safeguards.
- Maine State AGas victim2024-05-03
Enstar (US), Inc. reported an external system breach that occurred on May 30, 2023, and was discovered on October 21, 2023. The breach affected 88 Maine residents, compromising names and driver's license or non-driver identification card numbers. Enstar is offering 24 months of credit monitoring and identity theft restoration services to affected individuals.
- California State AGas victim2023-12-21
Enstar (US) Inc filed a supplemental data breach notification with the California Attorney General. The incident occurred between May 29 and May 31, 2023. The notice affects residents of California, Rhode Island, and other states. Social Security numbers and other personal information were potentially compromised. The company is offering 24 months of credit monitoring and identity restoration services through Experian. The specific cause of the breach and the total number of affected individuals are not detailed in the provided excerpts.
- Vermont State AGas victim2023-12-19
Enstar (US) Inc. notified consumers of a data breach involving its MOVEit Transfer server. The criminal group CL0P exploited a zero-day vulnerability (May 29-31, 2023) to exfiltrate data. Affected data included names and other elements. Enstar engaged forensic specialists, reported to law enforcement, and offered 24 months of credit monitoring. Rhode Island residents were explicitly identified as impacted.
- South Carolina State AGas victim2023-11-21
Enstar (US) Inc. notified South Carolina and other states of a data breach involving the MOVEit Transfer tool. The criminal group 'Clop' exploited a zero-day vulnerability (CVE-2023-34362) to access the server between May 29-31, 2023, and exfiltrated data. Enstar discovered the incident on October 21, 2023, after a comprehensive review. Affected data included names and government identifiers. Enstar reported to law enforcement, engaged forensic specialists, and offered 24 months of credit monitoring.
- Vermont State AGas victim2023-11-20
Enstar (US) Inc. disclosed a data breach resulting from the exploitation of a zero-day vulnerability in Progress Software's MOVEit Transfer tool by the CL0P criminal group. The incident occurred between May 29 and May 31, 2023. The breach exposed personal information including names and government identifiers. Enstar engaged forensic specialists, notified law enforcement, and offered 24 months of credit monitoring. 103 Rhode Island residents were explicitly identified as affected.
- Massachusetts State AGas victim2023-11-20
Enstar (US) Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-11-20. 240 Massachusetts residents were affected. The report records the breach type as electronic.
- Maine State AGas victim2023-11-20
Enstar (US) Inc. experienced an external system breach on May 29, 2023, which was discovered on October 21, 2023. The breach affected 69 Maine residents and compromised names and driver's license or non-driver identification card numbers. The company began notifying affected individuals on November 20, 2023, and offered 24 months of complimentary credit monitoring and identity theft restoration services through Experian.
- New Hampshire State AGas victim2023-11-20
Enstar US Inc. notified 105 New Hampshire residents on November 20, 2023, of a cybersecurity incident involving unauthorized access to personal information. The company engaged the FBI, implemented additional safeguards, and provided complimentary Experian credit monitoring services to affected individuals. The specific nature of the initial access vector was not detailed in the filing.
- Delaware State AGas victim2023-11-20
Enstar (US) Inc. notified individuals of a data breach involving the MOVEit Transfer zero-day vulnerability exploited by the CL0P criminal group. Unauthorized access occurred between May 29 and May 31, 2023, resulting in data exfiltration. The breach affected individuals across multiple jurisdictions, including 103 Rhode Island residents. Enstar engaged forensic specialists, reported to law enforcement, and offered 24 months of credit monitoring.
- Montana State AGas victim2023-11-20
Enstar (US) Inc. notified individuals of a data breach involving the MOVEit Transfer tool. An unauthorized actor, identified as the CL0P criminal group, exploited a zero-day vulnerability to access the server between May 29 and May 31, 2023, and exfiltrated data. Enstar engaged forensic specialists, notified law enforcement, and offered 24 months of credit monitoring. The incident was discovered on May 31, 2023, and notification was sent on November 20, 2023.
- California State AGas victim2023-11-20
Enstar (US) Inc. reported a data event occurring on May 29, 2023. The incident affected residents of California and several other states. The specific nature of the breach and the number of affected individuals are not disclosed in the provided summary or attachment excerpts, though credit monitoring was offered. The company is a financial services entity.
- Illinois State AGas victim2023-01-01
ENSTAR (US), INC. filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-799). The register records the breach as discovered on May 29, 2023. Additional entities named: MOVEIT. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.