Enstar Group
ent_3ee50ae79ec18dd7ce877175
Disclosures
3
State AG · Leak Site · 2 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
11
as filed · State AG ME
Leak-site claims
2
unverified actor claims
Identity resolution
- Canonical name
- Enstar Group
- Normalized
- enstar group— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 213800AMAL5QFXVUCN04
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- enstargroup.com
Disclosure history (3)newest first
- 🦞Maine State AGas victim2023-12-21
Enstar Group Limited reported a data breach impacting 11 residents of Maine. The breach was an external system hacking incident that occurred on May 29, 2023, and was discovered on October 21, 2023. The compromised data includes names and driver's license or non-driver identification card numbers. Enstar Group Limited began notifying affected individuals on December 19, 2023, and is offering 24 months of complimentary credit monitoring and identity theft restoration services through Experian.
- GLOBALLeak Siteas victim2023-06-29
Enstar Group
- GLOBALLeak Siteas victim2022-03-22
enstargroup.com
Subsidiary disclosures (newest 10)filed by group companies
◈ These filings were made by or about subsidiaries of Enstar Group — not by Enstar Group itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- ⛰️New Hampshire State AGvia ENSTAR (US) INC.2024-05-17
Allianz Global Risks U.S. Insurance Company notified the NH AG of a data breach affecting its third-party vendor, Enstar (US) Inc. Enstar suffered a security incident on May 31, 2023, due to an exploited zero-day vulnerability in MOVEit file transfer software. Unauthorized access occurred May 29-31, 2023, resulting in data exfiltration. Allianz learned of the incident on November 21, 2023, after Enstar notified its administrator, AZRA. Affected data includes PII such as names and government IDs. Enstar provided credit monitoring via Experian.
- 🐻California State AGvia ENSTAR (US) INC.2024-05-09
Enstar (US) Inc. disclosed that an unauthorized actor, identified as the criminal group CL0P, exploited a zero-day vulnerability in the MOVEit Transfer tool (provided by Progress Software Corp.) to access its server between May 29 and May 31, 2023. The actor exfiltrated data, including names and other personal information. Enstar launched an investigation with third-party forensic specialists, reported the incident to law enforcement, and is offering 24 months of credit monitoring and identity theft restoration services to affected individuals. The incident was discovered on May 31, 2023, when Progress Software publicly disclosed the vulnerability.
- 🍁Vermont State AGvia ENSTAR (US) INC.2024-05-03
Enstar (US) Inc. notified Vermont AG of a data breach involving the MOVEit Transfer zero-day vulnerability exploited by the CL0P criminal group. The incident occurred May 29-31, 2023. Enstar engaged forensic specialists, notified law enforcement, and offered 24 months of credit monitoring. Data accessed included names and other elements.
- 🦫Oregon State AGvia ENSTAR (US) INC.2024-05-03
Enstar (US), Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2024-05-03. The breach occurred during 5/30/2023 - 5/31/2023. The breach was discovered on 10/21/2023. 75,101 individuals were affected. Notice was sent on 11/20/202312/19/20235/3/2024.
- 🐻California State AGvia ENSTAR (US) INC.2024-05-03
Enstar (US) Inc filed a supplemental data breach notification with the California Attorney General. The incident occurred between May 30 and May 31, 2023. The notice offers 24 months of credit monitoring via Experian. Specific data types and affected counts are not detailed in the provided excerpts, though identity and financial data are implied by the remediation offer. The filing covers residents of multiple states including CA, RI, DC, MD, NM, NY, and NC.
- ⛰️New Hampshire State AGvia ENSTAR (US) INC.2024-05-03
Enstar US Inc. filed a supplemental notice with the New Hampshire Attorney General regarding a data event affecting individuals in multiple states. The incident, occurring in June 2023, involved unauthorized access to personal information including names, addresses, and Social Security numbers. Enstar notified the FBI, offered 24 months of credit monitoring via Experian, and implemented additional security safeguards.
- 🦞Maine State AGvia ENSTAR (US) INC.2024-05-03
Enstar (US), Inc. reported an external system breach that occurred on May 30, 2023, and was discovered on October 21, 2023. The breach affected 88 Maine residents, compromising names and driver's license or non-driver identification card numbers. Enstar is offering 24 months of credit monitoring and identity theft restoration services to affected individuals.
- 🐻California State AGvia ENSTAR (US) INC.2023-12-21
Enstar (US) Inc filed a supplemental data breach notification with the California Attorney General. The incident occurred between May 29 and May 31, 2023. The notice affects residents of California, Rhode Island, and other states. Social Security numbers and other personal information were potentially compromised. The company is offering 24 months of credit monitoring and identity restoration services through Experian. The specific cause of the breach and the total number of affected individuals are not detailed in the provided excerpts.
- 🍁Vermont State AGvia ENSTAR (US) INC.2023-12-19
Enstar (US) Inc. notified consumers of a data breach involving its MOVEit Transfer server. The criminal group CL0P exploited a zero-day vulnerability (May 29-31, 2023) to exfiltrate data. Affected data included names and other elements. Enstar engaged forensic specialists, reported to law enforcement, and offered 24 months of credit monitoring. Rhode Island residents were explicitly identified as impacted.
- 🍁Vermont State AGvia ENSTAR (US) INC.2023-11-20
Enstar (US) Inc. disclosed a data breach resulting from the exploitation of a zero-day vulnerability in Progress Software's MOVEit Transfer tool by the CL0P criminal group. The incident occurred between May 29 and May 31, 2023. The breach exposed personal information including names and government identifiers. Enstar engaged forensic specialists, notified law enforcement, and offered 24 months of credit monitoring. 103 Rhode Island residents were explicitly identified as affected.