CSIDB logo
Incident

Enders Insurance

Incident posture

Attack window
Apr 2020
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-26 16:09

Linked entities

Victim
Enders Insurance
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Colonial Park Realty Co., doing business as Enders Insurance, reported that an employee’s email account was compromised, resulting in a data breach that was discovered during an investigation. The company stated that it is notifying affected individuals out of an abundance of caution, noting there is no evidence of misuse of the information. The potentially exposed data includes names, dates of birth, Social Security numbers, driver’s license numbers, passport numbers, financial account details, payment card information, health insurance information, and medical treatment or diagnosis details.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

In April 2020 an employee email account used by Colonial Park Realty Co., operating as Enders Insurance, was compromised by an unauthorized actor. The compromise was not detected until May 7, 2020, when the organization identified the breach. Following detection, Enders launched an investigation to determine what data might have been accessed and to identify any individuals whose information was involved. The investigation continued for several months as the company worked to collect all relevant information. No public details were released about the specific methods used by the attacker beyond the email account compromise.

Enders’ investigation determined that the information potentially subject to unauthorized access included individuals’ names, dates of birth, Social Security numbers, driver’s license numbers, passport numbers, financial account information, payment card information, health insurance information, and medical treatment or diagnosis details. The company explicitly stated that there was no evidence that any of the accessed data had been misused or exploited by the attacker. Despite the absence of confirmed misuse, Enders chose to notify affected individuals as a precautionary measure. The notification was communicated in a press release dated February 22, 2021.

The press release informed customers that their personal information might have been viewed during the email account compromise. Enders explained that the notice was being sent out of an abundance of caution because there was no evidence of misuse. Enders also stated that it was investigating the incident to determine who was impacted.

Sources

Sources available to members: 1 source.

CSIDB