HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICHighContained
Vitality Nutrition
bd_04271a52b6c1bf45 · schema v1 · pii pii-v1
Full breach record for Vitality Nutrition →The Vitality Group, LLC reported a cybersecurity incident involving the MOVEit software vulnerability (Progress Software Corporation). The breach occurred on May 30, 2023, and was discovered on June 1, 2023. Approximately 4,392 individuals were affected, including 8 Maine residents. The incident involved the compromise of names and Social Security Numbers. The company provided written notification and offered 24 months of credit monitoring and identity theft protection services through Experian.
Maine clockDiscovered Jun 1, 2023 → Filed with AG Jun 30, 202329d ✓ ME AG ≤30d29 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_7380e4c0987b3826Montana State AGfiled 2023-07-06(6d gap)Verified
- bd_bbec978895f7fbc7HHS OCRfiled 2023-07-11(11d gap)Verified
- bd_26be677794ddc28bMaine State AGfiled 2023-07-17(17d gap)Verified
- bd_448dd79b72caf880Montana State AGfiled 2023-07-17(17d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/22e36023-20a3-411a-87bb-3d4578749921.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 30, 2023
- Raw hash
- a15c957a916768209fbb2fa3115b10d41f0bf4d754b51232cdf7bda3c41ebb3c
Reporting entity
- Name
- Vitality Nutritionnorm: vitality nutrition
- Domain
- vitalitynutrition.com
Victim entity
- Name
- Vitality Nutritionnorm: vitality nutrition
- Domain
- vitalitynutrition.com
Incident
- Discovered
- Jun 1, 2023
- Materiality determined
- —
- Notification sent
- Jun 28, 2023
- Affected individuals
- 4,392
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed data breach notice with the Maine Office of the Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 29 days(29 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 29d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Jun 1, 2023→ Filed with AG: Jun 30, 202329d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.