The Vitality Group
bd_ebfe3a7beed221c2 · schema v1 · pii pii-v1
Full breach record for The Vitality Group →7 incidents on fileVitality Group, LLC, a third-party vendor for Alert Holding Company, Inc., experienced a security incident involving the MOVEit file transfer software. The incident exploited a zero-day vulnerability discovered on May 30, 2023. Vitality detected the risk on June 1, 2023, and isolated the server. The breach affected 7 New Hampshire residents, exposing personal information including SSNs. Vitality patched the vulnerability, reset passwords, and offered credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
May 30, 2023
Begins
Jun 1, 2023
Discovered
Jul 18, 2023
Filed
vs. sector median
12 wks faster
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Maine State AGbd_26be677794ddc28b2023-07-17 · +1dVerified
- Montana State AGbd_448dd79b72caf8802023-07-17 · +1dVerified
- HHS OCRbd_bbec978895f7fbc72023-07-11 · +7dVerified
- Montana State AGbd_7380e4c0987b38262023-07-06 · +12dVerified
Show 1 more filing ↓Show fewer ↑up to 18d gap
- Maine State AGbd_04271a52b6c1bf452023-06-30 · +18dVerified
Filing propagation · 6 filings · 4 states
View merged incident ↗Pattern: first filing Jun 30 (ME), last Jul 18 (NH) — a 18-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.