HackingCustomer Data InvolvedPIIIDENTITY_BASICLowContained
Rachas, Inc
bd_b0db8010d479adab · schema v1 · pii pii-v1
Full breach record for Rachas, Inc →Rachas, Inc. d/b/a Chuze Fitness notified the NH Attorney General of a cybersecurity attack discovered on November 27, 2023, involving unauthorized network access. The incident affected current and former employees. Chuze Fitness engaged forensic investigators, secured the network, and offered 12 months of credit monitoring. No evidence of misuse was found.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_441ad4fcd76e860eIndiana State AGfiled 2024-01-18Verified
- bd_135d90567a0a67abCalifornia State AGfiled 2024-01-19(1d gap)Candidate
- bd_46e0c9f7412bde61Montana State AGfiled 2024-01-19(1d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/rachas-dba-chuze-fitness-20240118.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 18, 2024
- Raw hash
- b9c35cc2bf459eba5c0144e3f69f36a63e5a021532f71562b242ff033cdf4cf4
Reporting entity
- Name
- Rachas, Incnorm: rachas
Victim entity
- Name
- Rachas, Incnorm: rachas
Incident
- Discovered
- Nov 27, 2023
- Materiality determined
- —
- Notification sent
- Jan 18, 2024
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General Consumer Protection Bureau
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 7 weeks(52 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.