MalwareRansomwareStolen CredentialsData ExfiltratedSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
THE RESHAPOING AND NUTRITIONAL COMPANY LLC /
bd_a12588cf70a17877 · schema v1 · pii pii-v1
Full breach record for THE RESHAPOING AND NUTRITIONAL COMPANY LLC / →The Reshaping and Nutritional Company LLC notified customers of a data breach involving unauthorized access to servers operated by third-party provider Epic. An intruder installed malware, accessing customer data between December 8 and 9, 2024. Affected data includes names, addresses, phone numbers, emails, and Social Security numbers. The company engaged cybersecurity experts to remove malware and is cooperating with authorities.
California clockDiscovered Dec 9, 2024 → Notified Jan 12, 202534d ✓ CA 60-day OK7 weeks discovery → filing
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_ee4fe2d6fff3e7acWashington State AGfiled 2025-02-17(18d gap)Candidate
- bd_46a76e7d9ca5ccc8Indiana State AGfiled 2025-01-12(18d gap)Verified
- bd_ed532ed8b8c498d2Oregon State AGfiled 2025-02-24(25d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-598077
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 30, 2025
- Raw hash
- 1c6d3b079d73775fd1c214bdb21a5e7b0d3103bd8e24307a2663e27b6f787338
Reporting entity
- Name
- THE RESHAPOING AND NUTRITIONAL COMPANY LLC /norm: the reshapoing and nutritional
- Domain
- ardysslife.com
Victim entity
- Name
- THE RESHAPOING AND NUTRITIONAL COMPANY LLC /norm: the reshapoing and nutritional
- Domain
- ardysslife.com
Incident
- Discovered
- Dec 9, 2024
- Materiality determined
- —
- Notification sent
- Jan 12, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Cooperating with federal and state authorities to investigate the incident
- Third party
- via Epic
- Initial access
- supply_chain
Compliance
- Time to disclose
- 7 weeks(52 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 34d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 9, 2024→ Notified: Jan 12, 202534d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.