HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Jofit
bd_baa2d3531e2f8694 · schema v1 · pii pii-v1
Full breach record for Jofit →Jofit, LLC reported a data breach affecting customers who placed orders on jofit.com between January 18, 2019, and May 12, 2019. Suspicious activity was observed on May 13, 2019, leading to an investigation that identified unauthorized access to payment card data, including names, addresses, card numbers, expiration dates, and CVVs. Jofit engaged a security firm, enhanced website security, and notified payment card networks. No specific count of affected individuals was provided in the filing.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-149466
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 5, 2019
- Raw hash
- 221ef717db58518f824ddcd9b0624301c333ca9dc99d9199273583abf1bdcee5
Reporting entity
- Name
- Jofitnorm: jofit
- Domain
- jofit.com
Victim entity
- Name
- Jofitnorm: jofit
- Domain
- jofit.com
Incident
- Discovered
- May 13, 2019
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 12 weeks(84 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.