Vitality Group International, Inc.
ent_019ea9f3d82a5b5adc75581bf02af59b
Disclosures
9
Leak Site · State AG · 6 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
6
as filed · State AG NH
Leak-site claims
3
unverified actor claims
Identity resolution
- Canonical name
- Vitality Group International, Inc.
- Normalized
- vitality group— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 254900NVDG1TUKL7FL02
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- vitalitygroup.com
Disclosure history (9)newest first
- GLOBALLeak Siteas victim2023-08-31
Vitality: Engagement Platform That Works - Wellness Solutions
- GLOBALLeak Siteas victim2023-07-26
- New Hampshire State AGas reporting2023-07-18
CareSource Management Services LLC reported a security incident involving its vendor, Vitality Group, LLC. On May 30, 2023, a bad actor exploited a vulnerability in MOVEit software to access a server housing CareSource data. Vitality discovered the access on June 1, 2023, disconnected the server, and initiated a forensic investigation. The incident impacted 6 New Hampshire residents, exposing SSNs, names, DOBs, and gender. Vitality patched the vulnerability, reset passwords, and offered credit monitoring.
- California State AGas victim2023-06-30
Vitality Group International, Inc. experienced a data breach on May 30, 2023, due to a security vulnerability in the third-party MOVEit file transfer program. An unauthorized third party accessed the Vitality server for approximately two hours. The incident potentially exposed names, mailing addresses, dates of birth, email addresses, and Social Security numbers of U.S.-based employees of Brookfield and their partners/spouses. Vitality identified the risk on June 1, 2023, disconnected the server, and initiated forensic investigations. Affected individuals are offered 24 months of credit monitoring via Experian.
- Vermont State AGas victim2023-06-30
Vitality Group notified consumers of a data breach resulting from the exploitation of a zero-day vulnerability in Progress Software's MOVEit Transfer application. The incident, occurring around May 30, 2023, potentially exposed personal information including names, SSNs, dates of birth, and addresses for employees of Ambry Genetics and REALM IDx. Vitality Group contained the incident, patched systems, and offered two years of identity monitoring.
- Vermont State AGas victim2023-06-28
Vitality Group International Inc disclosed that an unauthorized third party exploited a critical zero-day vulnerability in MOVEit file transfer software to access and exfiltrate data files on May 30, 2023. The affected data included names, dates of birth, and limited health information (cholesterol, glucose, blood pressure, hemoglobin A1c). The company contained the incident by shutting down access to the impacted server and implemented additional security measures. Complimentary credit monitoring was offered to affected individuals.
- Massachusetts State AGas reporting2023-06-26
Vitality Management Company, LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-06-26. 2 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2023-06-26
Vitality Group International, Inc. notified members of a data breach involving MOVEit file transfer software. An unauthorized third party exploited a zero-day vulnerability to access and exfiltrate files containing personal information (name, DOB) and limited health information (cholesterol, glucose, blood pressure, hemoglobin A1c). The incident occurred on May 30, 2023. The company shut down the server, implemented security measures, and offered 24 months of credit monitoring via Experian.
- GLOBALLeak Siteas victim2022-10-24
vitalitygroup.com
Supply-chain cascadesreviewed and confirmed
- Vitality Group International, Inc.’s filing is one of at least 97 in the Progress Software Corporation supply-chain incident (2023).