MalwareRansomware0MID16BData ExfiltratedData EncryptedRansom DemandedCustomer Data InvolvedMulti-Stage ChainIDENTITY_BASICIDENTITY_GOVERNMENTCriticalContained
THE RESHAPOING AND NUTRITIONAL COMPANY LLC /
bd_dad3fa1f7a703737 · schema v1 · pii pii-v1
Full breach record for THE RESHAPOING AND NUTRITIONAL COMPANY LLC / →The Reshaping and Nutritional Company LLC DBA Ardyss Life experienced a ransomware attack in December 2024 involving its third-party hosting provider, EPIC. The threat actor '0MID16B' encrypted data, demanded ransom, and threatened to publish stolen customer PII (names, addresses, SSNs, ITINs). 307,000 individuals were affected, including 14,478 Maryland residents. The company migrated to new servers, engaged forensic investigators, and notified the FBI.
Maryland clock✗ MD AG >90d14 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed307,000 affectedView incident
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376553.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 13, 2025
- Raw hash
- 93f00cb97d3b8ad1bd5cd1e7346dd4888cde053999d39f0773107f705b7688e7
Reporting entity
- Name
- THE RESHAPOING AND NUTRITIONAL COMPANY LLC /norm: the reshapoing and nutritional
- Domain
- ardysslife.com
- Industry
- Retail
Victim entity
- Name
- THE RESHAPOING AND NUTRITIONAL COMPANY LLC /norm: the reshapoing and nutritional
- Domain
- ardysslife.com
- Industry
- Retail
Incident
- Discovered
- Dec 7, 2024
- Materiality determined
- —
- Notification sent
- Jan 12, 2025
- Affected individuals
- 307,000
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware· 0MID16B
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 ChannelT1190 Exploit Public-Facing Application
- Threat actor
- 0MID16BExternalFinancial
- Regulator citations
- Submitted a report of data breach to the FBI (Federal Bureau of Investigation)
- Third party
- via EPIC
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 14 weeks(95 days from discovery to filing)
- Compliance flags
- MD AG >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.