Confirmed breach. Intrusion Sep 17, 2023–Sep 28, 2023, discovered Sep 28, 2023 — the first regulatory filing landed 75 days later (flagged late). 2,703,320 individuals reported across the linked filings.
Regulatory clocksVermont✗ VT AG >45 bdayOregon✗ OR AG >45dMaine⏱ ME AG >30d · 82dWashington⏱ WA AG >30dHIPAA✓ HHS notifiedFull clock table in Litigation Timeline
HHS OCRState AGConfirmedLifecycle stage 2 of 3: ConfirmedUnverified claimConfirmedEnforcedhigh sensitivity
Affected (total reported)
14days
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
2,703,320
Data types
4
PHI · Identity (basic) · Government ID
Jurisdictions
9
CA DE FEDERAL ME MT NH OR VT
Linked filings
11
HHS OCR · State AG
Sensitive data
identity_government
Affected residents by state
per-filing reported counts
ME2,700,000
OR2,700,000
WA2,298
WA810
MT212
State AGs report only their own residents; bars show per-filing counts.
Timeline
Earliest sighting first · deep chronology in Litigation Timeline
11 filings across 9 jurisdictions · Dec 12, 2023 – Dec 26, 2023 · 3 milestones
Breach window
Sep 17, 2023
When the intrusion reportedly occurred, per the linked filings
Breach discoveredletter-grounded
Sep 28, 2023
Reported by VERMONT AG, CALIFORNIA AG, MAINE AG, OREGON AG, WASHINGTON AG filings
Breach discoveredconflicts with Sep 28, 2023AG web form
ESO Solutions, Inc. filed a data incident notice with the Delaware Attorney General. The breach affected individuals across multiple states (including DE, NY, CA, IL, etc.). The company offered identity monitoring services via Kroll. Specific attack details, dates, and affected counts were not disclosed in the filing.
🍁Vermont State AGlinked via same-victim cross-source · 100%
ESO Solutions, Inc. notified consumers of a ransomware incident detected on September 28, 2023. Unauthorized access encrypted systems, potentially exposing PHI, SSNs, and medical data. ESO engaged forensic investigators, notified the FBI, restored systems from backups, and offered 12 months of identity monitoring. No evidence of misuse found.
ESO Solutions, Inc., a Texas-based business associate, reported a ransomware attack to HHS OCR on 2023-12-18 that compromised PHI of 2,700,000 individuals stored on a network server. PHI included names, addresses, phone numbers, dates of birth, Social Security numbers, diagnoses/conditions, medications, and other treatment information. Covered entities took corrective actions including additional administrative and technical safeguards.
Affected (this filing): 2,700,000
HHS notified
Most recent
8 State AG filingsDec 19, 2023 – Dec 26, 2023ExpandCollapse
CAMEMTWAORNH
California State AG
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
ESO Solutions, Inc. experienced a ransomware incident on September 17, 2023, detected on September 28, 2023. An unauthorized third party accessed and encrypted systems, potentially acquiring protected health information (PHI), including SSNs, medical records, and insurance data for patients and minors. ESO engaged forensic experts, notified the FBI, and offered identity monitoring.
🦞Maine State AGlinked via same-victim cross-source · 100%
ESO Solutions, Inc. reported an external system breach (hacking) occurring on September 17, 2023, discovered on September 28, 2023. The incident affected approximately 2,700,000 individuals nationwide, including 132 Maine residents. Personal information acquired included names and Social Security Numbers. The company provided written notification on December 12, 2023, and offered 12 months of identity theft protection services.
Affected (this filing): 2,700,000
ME AG >30d · 82dME resident >60d · 75d
🦬Montana State AGlinked via same-victim cross-source · 100%
ESO Solutions Inc reported a data breach to the Montana Attorney General. The breach was reported on 2023-12-19. The breach occurred on 9/28/2023. 212 Montana residents were affected.
ESO Solutions, Inc., a business sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2023-09-28 and filed notice on 2023-12-20. 810 Washington residents were affected. 83 days elapsed between awareness and notification.
ESO Solutions, Inc., a health sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2023-10-23 and filed notice on 2023-12-20. 2,298 Washington residents were affected. 58 days elapsed between awareness and notification. 36 days to identify the breach. 0 days to contain the breach.
Affected (this filing): 2,298
WA AG >30d
🐻California State AGlinked via same-victim cross-source · 100%
ESO Solutions, Inc. experienced a ransomware incident detected on September 28, 2023, with unauthorized access occurring between September 17 and September 28, 2023. An unauthorized third party accessed and encrypted systems, potentially acquiring protected health information (PHI), including names, SSNs, and medical records. ESO engaged forensic specialists, notified the FBI, and offered identity monitoring services to affected individuals.
ESO Solutions, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-12-20. The breach occurred during 9/17/2023. The breach was discovered on 9/28/2023. 2,700,000 individuals were affected. Notice was sent on 12/12/2023.
Affected (this filing): 2,700,000
OR AG >45d
⛰️New Hampshire State AGlinked via same-victim cross-source · 100%
State AG breach notification filed by ESO Solutions, Inc. on December 26, 2023. The attachment content was empty, preventing extraction of incident details, dates, or data types.