Garden of Life, LLC
ent_bbf7054f5775b0cf
Disclosures
19
State AG · Leak Site · 13 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
43,219
nationwide · State AG OR
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- Garden of Life, LLC
- Normalized
- garden of life— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- gardenoflife.com
Disclosure history (19)newest first
- Massachusetts State AGas victim2025-12-12
Garden of Life, LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-12-12. 19 Massachusetts residents were affected.
- New Hampshire State AGas victim2025-12-12
Garden of Life, LLC notified the New Hampshire Attorney General of a data breach affecting 4 state residents. An unauthorized third party exploited an unpatched vulnerability in Oracle E-Business Suite between August 9-10, 2025, to access employee and contractor PII (names, SSNs, contact info). The company discovered the incident on November 11, 2025, isolated affected systems, engaged forensic experts, and sent notification letters on December 4, 2025, offering 24 months of identity protection services.
- Montana State AGas victim2025-12-12
Garden of Life, LLC notified affected individuals of a data breach where an unauthorized third party exploited an unreported Oracle E-Business Suite vulnerability to access employee and contractor data (names, SSNs, contact info) between Aug 9-10, 2025. The breach was discovered on Nov 11, 2025. The company patched the software, secured systems, and offered 24 months of identity theft protection.
- Maine State AGas victim2025-12-12
Garden of Life, LLC reported an external system breach where an unauthorized third party exploited a previously unknown vulnerability in Oracle E-Business Suite to access data between August 9-10, 2025. The incident was discovered on November 14, 2025, affecting 2,285 individuals (including 1 Maine resident). Compromised data included names, addresses, emails, phone numbers, and SSNs. Garden of Life is offering 24 months of identity theft protection services.
- Indiana State AGas victim2025-12-04
Garden of Life LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2025-08-09 and was reported on 2025-12-04. 47 Indiana residents were affected. 2,285 individuals affected in total.
- Nebraska State AGas victim2025-12-04
Garden of Life, LLC notified Nebraska AG of a data breach involving an unauthorized third party exploiting a previously unreported vulnerability in Oracle E-Business Suite. Access occurred August 9-10, 2025; discovered November 11, 2025. Data included names, addresses, emails, phone numbers, and SSNs of employees, contractors, and business partners. Remediation included patching, system security, and offering IDX identity protection services.
- GLOBALLeak Siteas victim2025-11-13
Garden of Life is a health and wellness company that produces a wide variety of nutritional supplements. The company's product line includes vitamins, probiotics, protein powders and bars, and more, all made using responsibly sourced, non-GMO, and organic ingredients. They focus on offering products that are traceable, pure, and high quality for a healthy lifestyle.
- Maryland State AGas victim2025-11-13
Garden of Life, LLC notified the Maryland Attorney General of a data incident affecting approximately 788 Maryland residents. Unauthorized access to a third-party payment processing software on the Garden of Life website occurred in July 2024 and was discovered on December 18, 2024. The incident exposed names, addresses, emails, credit/debit card numbers, expiration dates, and CVVs. Garden of Life engaged cybersecurity experts, isolated the affected system, and is sending notification letters to affected residents.
- Vermont State AGas victim2025-11-04
Garden of Life, LLC notified consumers of a data breach where an unauthorized third party exploited a previously unknown vulnerability in Oracle E-Business Suite to access personal data (names, addresses, SSNs) of employees, contractors, and business partners. The incident occurred in August 2025 and was discovered in November 2025. Garden of Life applied patches, secured systems, and is offering 24 months of identity theft protection services.
- Oregon State AGas victim2025-01-31
Garden of Life, LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2025-01-31. The breach occurred during 7/8/2024 - 12/18/2024. The breach was discovered on 12/18/2024. 43,219 individuals were affected. Notice was sent on 1/17/2024.
- Washington State AGas victim2025-01-17
Garden of Life, LLC reported unauthorized access to its payment processing software in July 2024, discovered on Dec 18, 2024. Access involved consumer names, addresses, emails, credit/debit card numbers, and CVVs. 1,082 Washington residents affected. Company engaged cybersecurity experts, isolated the system, and offered credit monitoring.
- Massachusetts State AGas victim2025-01-17
Garden of Life, LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-01-17. 1,295 Massachusetts residents were affected.
- Nebraska State AGas victim2025-01-17
Garden of Life, LLC, a general business entity filed a data breach notification with the Nebraska Attorney General. The breach was discovered on 2024-12-18 according to the AG's register. The breach is dated 2024-07-08. Nebraska residents were notified on 2025-01-17.
- New Hampshire State AGas victim2025-01-17
Garden of Life, LLC notified the NH Attorney General of a data incident affecting 354 NH residents. Unauthorized access to a third-party payment processing software on its website occurred in July 2024 and was discovered on Dec 18, 2024. Payment card info and consumer PII were accessed. Garden of Life engaged cybersecurity experts, isolated the system, and offered credit monitoring via IDX.
- Montana State AGas victim2025-01-17
Garden of Life, LLC notified Montana AG of a data breach where an unknown third party accessed its payment processing software in July 2024. The company discovered the incident on December 18, 2024. Compromised data included names, addresses, emails, credit/debit card numbers, and CVVs. Garden of Life engaged cybersecurity experts, isolated the system, and is offering credit monitoring and identity theft recovery services to affected consumers.
- Indiana State AGas victim2025-01-17
Garden of Life LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2024-07-08 and was reported on 2025-01-17. 626 Indiana residents were affected. 43,219 individuals affected in total.
- California State AGas victim2025-01-17
Garden of Life, LLC notified consumers that an unknown third party gained unauthorized access to its online payment software in July 2024. The company discovered the incident on December 18, 2024. Affected data includes names, addresses, email addresses, credit/debit card numbers, expiration dates, and CVV codes. The software was provided by a third-party vendor. Garden of Life engaged cybersecurity experts, isolated the system, and is offering credit monitoring services.
- Maine State AGas victim2025-01-17
Garden of Life, LLC reported an external system breach (hacking) occurring in July 2024, discovered on December 18, 2024. The incident compromised names, addresses, email addresses, credit/debit card numbers, and CVV numbers for approximately 43,219 individuals, including 254 Maine residents. Garden of Life engaged cybersecurity experts, isolated the affected vendor software, and offered 12 months of credit monitoring and identity theft protection services.
- Illinois State AGas victim2025-01-01
GARDEN OF LIFE, LLC filed a data-breach notice with the Illinois Attorney General in January 2025 (case 25-01-049). The register records the breach as discovered on December 18, 2024. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.