Jofit
ent_66d88ba982e6e52e479140db
Disclosures
9
State AG · 5 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
105
as filed · State AG MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Jofit
- Normalized
- jofit— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- jofit.com
Disclosure history (9)newest first
- New Hampshire State AGas victim2019-08-06
JoFit, LLC notified the NH Attorney General of a security incident where unauthorized access to payment card data (names, addresses, card numbers, CVVs) occurred between Jan 18 and May 12, 2019. Suspicious activity was detected on May 13, 2019. 20 NH residents were notified on Aug 5, 2019. JoFit engaged a security firm and enhanced website security.
- Massachusetts State AGas victim2019-08-05
JoFit, LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-08-05. 82 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2019-08-05
JoFit, LLC notified customers of a breach involving payment card data (name, address, card number, CVV) for orders placed between Jan 18 and May 13, 2019. Suspicious activity was detected on May 13, 2019. The company engaged a security firm and enhanced website security.
- California State AGas victim2019-08-05
Jofit, LLC notified the California Attorney General of a data breach affecting payment card information. Unauthorized access to customer payment card data (including card numbers, expiration dates, CVVs, names, and addresses) occurred between January 18, 2019, and May 13, 2019. The company detected suspicious activity on May 13, 2019, and engaged a third-party security firm. The investigation confirmed potential unauthorized access to data entered on the website checkout page. Jofit enhanced website security measures and coordinated with payment card networks.
- South Carolina State AGas victim2017-02-27
JoFit notified South Carolina residents of a cybersecurity attack targeting its website in mid-January 2017. The incident potentially exposed customer names and credit card payment information. JoFit engaged law enforcement and a forensic consultant, and offered one year of complimentary identity monitoring via Epiq.
- Massachusetts State AGas victim2017-02-27
JoFit reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-02-27. 105 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2017-02-24
JoFit notified Montana residents of a cybersecurity attack targeting its website in mid-January 2017. The incident potentially exposed customer credit card information and personal names. JoFit engaged law enforcement and forensic consultants, and offered one year of identity monitoring via Epiq.
- New Hampshire State AGas victim2017-02-22
JoFit, a clothing and accessories company, notified the NH Attorney General in February 2017 that its website was targeted by a cybersecurity attack in mid-January 2017. The attack exploited a vulnerability in the website, potentially exposing customer names and credit card information. Approximately 38 New Hampshire residents were likely affected. JoFit engaged forensic consultants and notified law enforcement, offering one year of credit monitoring.
- California State AGas victim2017-02-22
JoFit, a consumer fitness company, disclosed a data breach in mid-January 2024 where its website was targeted by a cybersecurity attack exploiting a vulnerability to acquire customer credit card information. The incident exposed names and credit card payment data. JoFit notified law enforcement, hired forensic consultants, and provided one year of complimentary identity monitoring via Equifax to affected individuals.