HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedPIIFINANCIAL_ACCOUNTLowActive
Jofit
bd_bf4943e430adc89c · schema v1 · pii pii-v1
Full breach record for Jofit →JoFit, a consumer fitness company, disclosed a data breach in mid-January 2024 where its website was targeted by a cybersecurity attack exploiting a vulnerability to acquire customer credit card information. The incident exposed names and credit card payment data. JoFit notified law enforcement, hired forensic consultants, and provided one year of complimentary identity monitoring via Equifax to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-66446
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 22, 2017
- Raw hash
- 2b257656fb0bb1e0170ad543aeec2ca8f314e0e17d78036388c94de371758ead
Reporting entity
- Name
- Jofitnorm: jofit
- Domain
- jofit.com
Victim entity
- Name
- Jofitnorm: jofit
- Domain
- jofit.com
Incident
- Discovered
- —
- Materiality determined
- Feb 16, 2024
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.