CSIDB logo
Incident

Endue Software

Incident posture

Attack window
Feb 2025
Location
United States of America
Status
Ongoing
CIA posture
Available to members
Updated
2026-09-02 12:15

Linked entities

Victim
Endue Software
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2025
Discovered
Feb 2025
Disclosed
Apr 2025
Resolved
Pending

Summary

A cybersecurity event at Endue Software resulted in unauthorized access to certain internal computer systems for a brief period, during which files were copied. The breach potentially exposed personal information including full names, addresses, Social Security numbers, dates of birth, and medical record numbers, though the specific information affected varied by individual. Upon discovering the activity, Endue secured its environment, initiated an investigation, and undertook an extensive review of the involved files to determine what sensitive information was contained and to whom it related. Notice letters are being mailed to affected individuals for whom valid mailing address information is available, and a dedicated assistance line has been established to address questions. The company stated it is not aware of any actual or attempted identity fraud resulting from the incident.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On April 11, 2025, Endue Software issued a public notice of a data privacy event that had occurred approximately two months earlier. According to the notice posted on the company's website, Endue learned on February 17, 2025 that there had been potential unauthorized access to certain Endue systems. Upon discovering the activity, Endue immediately took steps to secure its environment and initiated an investigation to determine the nature and scope of the activity. The investigation determined that the activity was the result of a cybersecurity event in which an unauthorized actor accessed certain computer systems for a brief period of time on February 16, 2025. During that window of access, files from certain internal systems were copied. Endue subsequently undertook an extensive review of the involved files to determine whether they contained sensitive information, to whom the information related, and to which clients the affected individuals' information had been provided from. The notice stated that Endue was not aware of any actual or attempted identity fraud resulting from the incident at the time of publication.

The types of information potentially impacted varied by individual and included full name, address, Social Security number, date of birth, and/or medical record number. Endue indicated that it was in the process of mailing notice letters to individuals whose protected information was contained within the files at issue and for whom it had valid mailing address information. The company provided contact channels for further inquiries, including a dedicated assistance line at 1-833-998-5748 and a mailing address at 29 North Street, Unit A, Portland, ME 04101. The notice also included detailed information for affected individuals on how to monitor their accounts, place fraud alerts or credit freezes, and contact the three major U.S. credit reporting bureaus—Equifax, Experian, and TransUnion—as well as the Federal Trade Commission and applicable state Attorneys General. Endue specifically stated that the notice had not been delayed by law enforcement.

Sources

Sources available to members: 1 source.

CSIDB