HackingVulnerability ExploitTargetedCREDENTIALSIDENTITY_BASICLowContained
Jefit, Inc.
bd_8f36308f78c3f03b · schema v1 · pii pii-v1
Full breach record for Jefit, Inc. →Jefit, Inc. notified California AG of a cyber-incident in August 2021 where unauthorized access exposed user account usernames, email addresses, hashed passwords, and IP addresses. No financial data was involved. The company patched the vulnerability, conducted forensic investigations, and contacted law enforcement.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-539268
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 18, 2021
- Raw hash
- c960248d4de6b2a0a5621c782365759595284c987b9a4e620e9ba6b0fd2c1cbf
Reporting entity
- Name
- Jefit, Inc.norm: jefit
Victim entity
- Name
- Jefit, Inc.norm: jefit
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALSIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.