HackingVulnerability ExploitZero-DaySupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Vitality Group International, Inc.
bd_e86d30f8d284d89c · schema v1 · pii pii-v1
Full breach record for Vitality Group International, Inc. →Vitality Group notified consumers of a data breach stemming from a zero-day vulnerability in Progress Software's MOVEit Transfer application. The attack, identified on May 30, 2023, compromised personal information including names, SSNs, and addresses of employees of partner companies Ambry Genetics and REALM IDx. Vitality disabled access, conducted forensic investigations, patched systems, and offered two years of Experian IdentityWorks monitoring.
Leak gap clock✗ Leak >180d4 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 3 about the same incident.View merged incident
A leak claim by dispossessor about this victim predates this filing by 249 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_6b3a2c4ab1bfdb6dCalifornia State AGfiled 2023-06-30Candidate
- bd_51ffc537e3fe379aVermont State AGfiled 2023-06-28(2d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-06-30-realm-idx-vitality-group-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 30, 2023
- Raw hash
- 73553c96b87df518ddcd40fe602fd8c92d2f2a8bf12c7cbc4432598ddb54ccb6
Reporting entity
- Name
- Vitality Group International, Inc.norm: vitality group
- Domain
- vitalitygroup.com
Victim entity
- Name
- Vitality Group International, Inc.norm: vitality group
- Domain
- vitalitygroup.com
Incident
- Discovered
- May 30, 2023
- Materiality determined
- —
- Notification sent
- Jun 30, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 4 weeks(31 days from discovery to filing)
- Compliance flags
- Leak >180dVT AG >14 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.