Confirmed breach. Intrusion Jan 22, 2025, discovered Jan 22, 2025 — the first regulatory filing landed 40 days later. 16,379 individuals reported across the linked filings.
Discovery variance · Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster; needs two dated filings.
Regulatory clocksMaryland⏱ MD AG >30dFull clock table in Litigation Timeline
State AGConfirmedLifecycle stage 2 of 3: ConfirmedUnverified claimConfirmedEnforcedhigh sensitivity
Affected (total reported)
16,379
Data types
3
Identity (basic) · Government ID · Credentials
Jurisdictions
2
IN MD
Linked filings
2
all State AG
Sensitive data
identity_government
Timeline
Earliest sighting first · deep chronology in Litigation Timeline
Breach window
Jan 22, 2025
When the intrusion reportedly occurred, per the linked filings
Breach discovered
Jan 22, 2025
Reported by MARYLAND AG filing
40 days
🏎️Indiana State AGFirst filinglinked via multistate filing link · 100%
Estrella Franchising LLC dba Estrella Insurance reported a data breach to the Indiana Attorney General. The breach occurred on 2025-01-22 and was reported on 2025-03-03. 13 Indiana residents were affected. 16,379 individuals affected in total.
Estrella Franchising, LLC d/b/a Estrella Insurance reported a ransomware incident detected on January 22, 2025, impacting approximately 16,379 individuals, including 8 Maryland residents. Affected data included names, contact info, SSNs, driver's license numbers, and online account credentials. Estrella reset passwords, restored backups, engaged forensic experts, and notified law enforcement. Affected individuals received 24 months of Experian IdentityWorks services.
Affected (this filing): 16,379
MD AG >30d
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.