Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICCREDENTIALSLowContained
Bodybuilding.com, LLC
bd_fb96d8d61123e016 · schema v1 · pii pii-v1
Full breach record for Bodybuilding.com, LLC →Bodybuilding.com (a subsidiary of Vitalize LLC) notified customers of a data breach involving unauthorized access to systems. The incident originated from a phishing email in July 2018, discovered in February 2019. Potentially accessed data included names, emails, passwords, and billing addresses. No full credit card numbers were stored. The company engaged forensic consultants, reset passwords, and coordinated with law enforcement.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2019/06/Vitalize-LLC-Customer-Notice.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 1, 1971
- Raw hash
- ffa75a5551d6568317a7689074a69ae61ae895ceda6ceed26ee3c2d0202226c5
Reporting entity
- Name
- Bodybuilding.com, LLCnorm: bodybuildingcom
- Domain
- bodybuilding.com
Victim entity
- Name
- Bodybuilding.com, LLCnorm: bodybuildingcom
- Domain
- bodybuilding.com
Incident
- Discovered
- Feb 1, 2019
- Materiality determined
- —
- Notification sent
- Apr 24, 2019
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICCREDENTIALS
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Regulator citations
- coordinating with law enforcement to investigate the incident
- Initial access
- phishing_link
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.