Andesa
ent_914573eac67654216561a25b
Disclosures
10
State AG · Leak Site · 8 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
2,296
nationwide · State AG ME
Leak-site claims
2
unverified actor claims
Identity resolution
- Canonical name
- Andesa
- Normalized
- andesa— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- andesaservices.com
Disclosure history (10)newest first
- New Hampshire State AGas victim2023-10-31
Andesa Services Inc. notified the NH AG of a MOVEit Transfer vulnerability exploitation (May 30-31, 2023) affecting ~168 NH residents. Data included PII/identity info. Andesa patched, investigated, notified FBI, and offered credit monitoring.
- Maine State AGas victim2023-10-25
Andesa Services, Inc. reported a data breach affecting 2,296 individuals. The incident involved unauthorized access and extortion, occurring on May 30, 2023, and discovered on August 2, 2023. The compromised information included names and Social Security numbers. Andesa Services began notifying affected individuals on October 23, 2023, and offered 12 months of credit monitoring services through Experian.
- New Hampshire State AGas victim2023-10-25
Andesa Services, Inc. notified the New Hampshire Attorney General of a cybersecurity incident involving the MOVEit Transfer server. An actor exploited vulnerabilities to access the server between May 30 and May 31, 2023, and exfiltrated data. Andesa Services notified 14 New Hampshire residents on October 23, 2023, offering credit monitoring through Experian. The incident involved personal information and government identifiers.
- Massachusetts State AGas victim2023-10-25
Andesa Services, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-10-25. 96 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2023-10-23
Andesa Services, Inc. notified Montana residents of unauthorized access to its MOVEit Transfer server between May 30-31, 2023, exploiting a vulnerability disclosed by Progress Software Corp. on May 31, 2023. The incident involved personal information. Andesa engaged third-party cybersecurity specialists, applied patches, and offered credit monitoring services.
- Indiana State AGas victim2023-10-23
Andesa Services, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2023-05-30 and was reported on 2023-10-23. 8 Indiana residents were affected. 2,296 individuals affected in total.
- California State AGas victim2023-10-23
Andesa Services disclosed that an unknown actor exploited a previously unknown vulnerability in Progress Software's MOVEit Transfer tool, accessing data between May 30-31, 2023. The incident affected 406 Rhode Island residents. Andesa applied patches, launched a third-party investigation, and offered credit monitoring.
- Vermont State AGas victim2023-10-23
Andesa Services notified consumers of a data breach involving the MOVEit Transfer tool, exploited via a previously unknown vulnerability (Progress Software Corp). Unauthorized access occurred May 30-31, 2023. Data accessed included PII and government IDs. Andesa engaged third-party cybersecurity specialists, applied patches, and offered credit monitoring. 406 Rhode Island residents were explicitly identified as affected.
- GLOBALLeak Siteas victim2023-08-27
andesaservices.com
- GLOBALLeak Siteas victim2023-06-23
Policy Lifecycle Solutions Provider for Life Insurance & Annuities Industry - Andesa