HackingVulnerability ExploitZero-DayData ExfiltratedSupply Chain (3P Vendor)IDENTITY_BASICHEALTH_BASICLowContained
Vitality Group International, Inc.
bd_51ffc537e3fe379a · schema v1 · pii pii-v1
Full breach record for Vitality Group International, Inc. →Vitality Group International Inc notified consumers of a data breach involving its MOVEit file transfer software. An unauthorized third party exploited a zero-day vulnerability to exfiltrate files containing names, dates of birth, and limited health information (cholesterol, glucose, blood pressure, A1c). The incident occurred on May 30, 2023. Vitality contained the breach and offered 24 months of Experian credit monitoring.
Leak gap clock✗ Leak >180d29 days discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 3 about the same incident.View merged incident
A leak claim by dispossessor about this victim predates this filing by 247 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_6b3a2c4ab1bfdb6dCalifornia State AGfiled 2023-06-30(2d gap)Candidate
- bd_e86d30f8d284d89cVermont State AGfiled 2023-06-30(2d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-06-28-vitality-group-international-inc-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 28, 2023
- Raw hash
- d4dc1fb4b3d660296c715efd72cd04467845cf3d3c4775090b0e0e58f4ff1fcd
Reporting entity
- Name
- Vitality Group International, Inc.norm: vitality group
- Domain
- vitalitygroup.com
Victim entity
- Name
- Vitality Group International, Inc.norm: vitality group
- Domain
- vitalitygroup.com
Incident
- Discovered
- May 30, 2023
- Materiality determined
- Jun 22, 2023
- Notification sent
- Jun 22, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 29 days(29 days from discovery to filing)
- Compliance flags
- Leak >180dVT AG >14 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.