Vitality
ent_7d69af7ac34e4de1a55f373c
Disclosures
3
State AG · 1 jurisdiction
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
9
as filed · State AG NH
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Vitality
- Normalized
- vitality— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- shopvitality.com
Disclosure history (3)newest first
- New Hampshire State AGas reporting2023-07-17
CoStar Realty Information, Inc. (via vendor Vitality Group, LLC) disclosed a MOVEit zero-day vulnerability incident. Unauthorized access occurred May 30, 2023. Vitality detected the risk June 1, 2023, disconnected the server, and applied patches. 2 NH residents affected; data included name, address, DOB, email, SSN. Notification sent July 17, 2023, with 24 months credit monitoring.
- New Hampshire State AGas victim2023-07-14
The Vitality Group, LLC reported a security incident involving the MOVEit file transfer vulnerability. The zero-day vulnerability was identified on May 30, 2023, and detected by Vitality on June 1, 2023. An unauthorized third party accessed the server for a two-hour span. 9 New Hampshire residents were affected, with personal information including names and Social Security numbers potentially exposed. Vitality disconnected the server, applied patches, reset passwords, and offered credit monitoring via Experian.
- New Hampshire State AGas reporting2023-07-03
Kuecker Pulse Integration, LP (via vendor The Vitality Group, LLC) notified NH AG of a MOVEit vulnerability exploit. Unauthorized access occurred June 1-11, 2023, affecting 2 NH residents' PII (SSN, DOB, etc.). Vitality isolated the server, patched, reset passwords, and engaged forensics. 24-month credit monitoring offered.