ENSTAR (US) INC. PROVIDES NOTICE OF DATA SECURITY EVENT
St. Petersburg, Florida, May 3, 2024 - Enstar (US) Inc. ("Enstar") is providing notice of a data security/breach incident that affects the privacy of certain information stored on its systems. Enstar focuses on the acquisition and management of re/insurance companies and portfolios of re/insurance businesses from other insurance companies and groups. Although Enstar is currently unaware of any fraudulent misuse of any individual's information in connection with this incident, Enstar is providing details of the incident, their response, and steps individuals may take to better protect against possible misuse of their information, should they feel it appropriate to do.
On May 31, 2023, Progress Software Corp. publicly disclosed zero-day vulnerabilities that impacted the MOVEit Transfer tool. As a user of that tool, Enstar moved quickly to apply all software updates provided by the vendor to address vulnerabilities associated with the application and undertook recommended mitigation steps. Enstar promptly launched an investigation, with the assistance of third-party forensic specialists, to determine the nature and scope of the potential impact of the vulnerabilities' presence on our MOVEit Transfer server and on the data it stored. Enstar's investigation determined that an unauthorized actor (subsequently identified as the criminal group known as 'CL0P') exploited this zero-day vulnerability, accessed the MOVEit Transfer server between May 29, 2023 and May 31, 2023, and exfiltrated data over that time. Enstar undertook a time-consuming and comprehensive review of the impacted data to understand the contents of that data and to whom that data relates. It was determined, as a result of the initial review, that Enstar didn't have mailing addresses for all potentially impacted individuals. Enstar began providing notice of this event on November 20, 2023 to individuals for whom Enstar had a mailing address. Enstar then conducted a review of its records to try to locate additional addresses. This review was completed on March 22, 2024. On May 3, 2024, Enstar mailed the last set of letters but couldn't locate addresses for all potentially impacted individuals.
While Enstar is currently unaware of any misuse of information relating to this incident, the data that was present within the accessible files at the time of incident includes an individual's name and one or more of Social Security number, driver's license number, state issued identification number, individual taxpayer identification number, financial account information, medical information, health insurance information, and email address and password.
Enstar has mailed notification letters to the individuals identified as impacted by this incident, for whom it has valid mailing addresses. If an individual did not receive a letter but would like to know if they are affected, they may call Enstar's dedicated assistance line, provided below.
Enstar takes the confidentiality, privacy, and security of information in their care seriously. Upon discovery, Enstar immediately commenced an investigation to confirm the nature and scope of the incident. Enstar reported this incident to law enforcement, and has taken steps to implement additional safeguards relating to data privacy and security.
Enstar encourages potentially impacted individuals to remain vigilant against incidents of identity theft and fraud, to review their account statements, and to monitor their credit reports for suspicious activity. Under U.S. law, individuals are entitled to one free credit report annually from each of the three major credit reporting bureaus. To order a free credit report, visit www.annualcreditreport.com or call toll-free, 1-877-322-8228. Individuals may also contact the three major credit bureaus directly to request a free copy of their credit report, place a fraud alert, or a security freeze.
Individuals with questions about this incident may call Enstar's dedicated assistance line at 833-931-8588, Monday through to Friday from 9 am - 11 pm Eastern, or Saturday and Sunday from 11 am - 8 pm Eastern (excluding major U.S. holidays). Be prepared to provide engagement number B121258. Additional details about this event can also be found at www.enstargroup.com/notice-of-data-security-incident.
Media Contact:
Kathie Ruane
+44 207 680 4531
/PRNewswire -- May 3, 2024/
SOURCE Enstar Group Limited