HackingVulnerability ExploitSupply Chain (3P Vendor)N-DayTargetedIDENTITY_BASICPIILowContained
Jonas Fitness, Inc.
bd_b5b590074f3adf42 · schema v1 · pii pii-v1
Full breach record for Jonas Fitness, Inc. →Jonas Fitness, Inc. notified consumers of a data breach involving its MOVEit Transfer file-sharing software, exploited via a vulnerability disclosed by Progress Software on May 31, 2023. The incident, occurring on June 1, 2023, potentially exposed customer names and other personal data. Jonas Fitness engaged cybersecurity experts, disabled the MOVEit console, and is deploying patches. No specific affected count was provided in the notice.
Vermont clock⏱ VT AG >14 bday9 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_60bbe20ecbfbd257Maine State AGfiled 2023-08-01Candidate
- bd_6de643245874becaNew Hampshire State AGfiled 2023-08-07(6d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-08-01-jonas-fitness-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 1, 2023
- Raw hash
- 470e0d1f0ea00d910ee3aaa7e7b31d191521d47ea717b79f87817ccf40f21d17
Reporting entity
- Name
- Jonas Fitness, Inc.norm: jonas fitness
- Domain
- jonasfitness.com
Victim entity
- Name
- Jonas Fitness, Inc.norm: jonas fitness
- Domain
- jonasfitness.com
Incident
- Discovered
- Jun 1, 2023
- Materiality determined
- Aug 1, 2023
- Notification sent
- Aug 1, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1190 Exploit Public-Facing Application
- Threat actor
- External
- Third party
- via Progress Software Corporation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(61 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.