HackingVulnerability ExploitSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Garden of Life, LLC
bd_d26e0355effbbe56 · schema v1 · pii pii-v1
Full breach record for Garden of Life, LLC →Garden of Life, LLC notified consumers that an unknown third party gained unauthorized access to its online payment software in July 2024. The company discovered the incident on December 18, 2024. Affected data includes names, addresses, email addresses, credit/debit card numbers, expiration dates, and CVV codes. The software was provided by a third-party vendor. Garden of Life engaged cybersecurity experts, isolated the system, and is offering credit monitoring services.
California clockDiscovered Dec 18, 2024 → Notified Jan 17, 202530d ✓ CA 60-day OK4 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_16db60a5ee4cc990Washington State AGfiled 2025-01-17Candidate
- bd_a7462c85743ddfbdNew Hampshire State AGfiled 2025-01-17Verified
- bd_b5e7686779303432Montana State AGfiled 2025-01-17Verified by operator
- bd_c193468e78213729Indiana State AGfiled 2025-01-17Verified
Show 2 more filings ↓Show fewer ↑up to 14d gap
- bd_d58348fb580f2733Maine State AGfiled 2025-01-17Verified
- bd_cfdb75a63e580415Oregon State AGfiled 2025-01-31(14d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-597503
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 17, 2025
- Raw hash
- afa76b96ebbc6a8637a9df77ef15e1c9246ea3a39e0c39498693515d243fc450
Reporting entity
- Name
- Garden of Life, LLCnorm: garden of life
- Domain
- gardenoflife.com
Victim entity
- Name
- Garden of Life, LLCnorm: garden of life
- Domain
- gardenoflife.com
Incident
- Discovered
- Dec 18, 2024
- Materiality determined
- —
- Notification sent
- Jan 17, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- External
- Third party
- via Payment software vendor
- Initial access
- supply_chain
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 30d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 18, 2024→ Notified: Jan 17, 202530d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.