Menu
Browse

Cyber Incident Victim: Enstar (US) Inc.

Date:

May 2023

Location:

United States of America

Summary

An external system breach at Enstar (US) Inc. compromised the personal data of over 64,000 individuals. The incident involved the acquisition of names combined with driver's license or state identification numbers. The company discovered the breach months after it occurred and subsequently offered affected persons two years of complimentary credit monitoring and identity theft restoration services.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

A data breach occurred at Enstar (US) Inc., a commercial entity based at 150 2nd Ave North, 3rd Floor, St. Petersburg, Florida, 33701. The incident was an external system breach resulting from hacking. The unauthorized access to the company's systems took place on May 29, 2023. The breach was not discovered until October 21, 2023, a gap of nearly five months between the initial intrusion and its detection by the organization.

Cyber Incident Image

The breach compromised the personal information of 64,934 individuals in total. This figure included 69 residents of the state of Maine. The specific category of information acquired during the incident consisted of names or other personal identifiers in combination with driver's license numbers or non-driver identification card numbers. This combination of data elements is considered sensitive and could potentially be misused for identity theft or other fraudulent activities.

Following the discovery of the breach on October 21, 2023, Enstar initiated its response procedures. The company undertook an investigation to determine the nature and scope of the incident. This process involved identifying which individuals were affected and what specific types of their personal information were involved in the security event. The company also reported the breach to the relevant authorities as required by law.

The entity responsible for managing the breach notification process was Richard Grainger, who held the title of Data Protection Officer for Enstar (US) Inc. His contact information, including a telephone number with a United Kingdom country code and an email address, was provided in the official filing. The firm name listed for the submission was Enstar (US) Inc., confirming his relationship to the affected entity.

Enstar elected to provide written notification to all affected consumers. The mailing of these notices to impacted individuals occurred on November 20, 2023. This date marked the formal communication from the company to the persons whose data was compromised, informing them of the breach and the potential risk to their personal information. A copy of the notice intended for affected Maine residents was filed with the state's authorities under the title "Enstar Group Limited - Notice of Data Event - ME.pdf."

As a remedial measure to help protect the affected individuals from potential harm, Enstar offered complimentary identity theft protection services. The company provided access to 24 months of credit monitoring and identity theft restoration services. These services were furnished through Experian Consumer Services. The offering of two years of such protection is a common practice intended to monitor credit reports for signs of fraudulent activity and to provide assistance in restoring a victim's identity should it be misused. The filing confirmed that no breach notifications had been issued by the entity within the twelve months preceding this incident. The company also confirmed that because the number of affected Maine residents was 69, it did not exceed the 1,000-person threshold that would have required additional notification to consumer reporting agencies under Maine state law. The incident was formally documented with the Office of the Maine Attorney General on May 31, 2023, which was two days after the breach occurred but several months before the breach was actually discovered and investigated by the company.

Sources
Sources available to members
1 source