Jonas Fitness, Inc.
ent_6d8de69841e0087d79fe6a55
Disclosures
6
State AG · Leak Site · 6 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
4,816
nationwide · State AG ME
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- Jonas Fitness, Inc.
- Normalized
- jonas fitness— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- jonasfitness.com
Disclosure history (6)newest first
- New Hampshire State AGas victim2023-08-07
Jonas Fitness, Inc. notified the New Hampshire AG of a breach involving its MOVEit Transfer application. An unauthorized actor exploited a zero-day vulnerability on June 1, 2023, to access personal information of the company's clients' members. Six New Hampshire residents were notified. The company engaged forensic experts, applied patches, and discontinued the vulnerable application.
- Massachusetts State AGas victim2023-08-01
Jonas Fitness, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-08-01. 9 Massachusetts residents were affected. The report records the breach type as electronic.
- Maine State AGas victim2023-08-01
Jonas Fitness, Inc., a point-of-sale vendor, reported an external system breach (hacking) that was discovered on June 1, 2023, the same day it occurred. The breach affected one Maine resident, compromising their name in combination with their driver's license or non-driver identification card number. The affected individual was notified in writing on August 1, 2023.
- Indiana State AGas victim2023-08-01
Jonas Fitness, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2023-06-01 and was reported on 2023-08-01. 1 Indiana residents were affected. 4,816 individuals affected in total.
- Vermont State AGas victim2023-08-01
Jonas Fitness, Inc., a software provider for fitness facilities, notified consumers of a data breach resulting from a previously unknown vulnerability in Progress Software's MOVEit Transfer application. The vulnerability was announced on May 31, 2023, and unauthorized access to files occurred on June 1, 2023. Affected data may include names and other personal information. Jonas Fitness engaged cybersecurity experts, discontinued MOVEit console access, and applied patches.
- GLOBALLeak Siteas victim2023-07-19
Supply-chain cascadesreviewed and confirmed
- Jonas Fitness, Inc.’s filing is one of at least 97 in the Progress Software Corporation supply-chain incident (2023).