HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedPHIHEALTH_BASICIDENTITY_BASICLowContained
AgelessRx
bd_8f52a16fa04c3b48 · schema v1 · pii pii-v1
Full breach record for AgelessRx →AgelessRx notified the California Attorney General of an incident where an unauthorized actor accessed help-desk tickets between April 17 and April 22, 2026. The company became aware of the potential unauthorized access on April 22, 2026. Affected data includes names, dates of birth, health diagnoses, conditions, medications, and treatment information. AgelessRx engaged third-party specialists, implemented additional cybersecurity measures, and is offering 12 months of credit monitoring and identity restoration services via Experian to affected individuals.
California clockDiscovered Apr 22, 2026 → Notified Jun 23, 202662d ✗ CA 30-day late9 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_eae946726b1348dbVermont State AGfiled 2026-06-24Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-625334
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 24, 2026
- Raw hash
- c0e2905237b1d63c50ca3bc1d3fa0089aca5c56627b3d48d0a5b8d10ed38fc25
Reporting entity
- Name
- AgelessRxnorm: agelessrx
- Domain
- customer.agelessrx.com
Victim entity
- Name
- AgelessRxnorm: agelessrx
- Domain
- customer.agelessrx.com
Incident
- Discovered
- Apr 22, 2026
- Materiality determined
- —
- Notification sent
- Jun 23, 2026
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
Compliance
- Time to disclose
- 9 weeks(63 days from discovery to filing)
- Compliance flags
- CA 30-day late · 62dCA AG copy ≤15d · 1d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 22, 2026→ Notified: Jun 23, 202662d 30 calendar days CA 30-day late California Consumers notified: Jun 23, 2026→ AG copy submitted: Jun 24, 20261d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.