If you were affected, free legal review is available — no obligation.
Learn how to participate in the class action and what compensation you may be entitled to.
Join the Class Action →Use our verification tool to confirm your letter matches this official AG filing.
Verify My Notice LetterThis case file references a public filing made with the state filing in NH. This website is not affiliated with, endorsed by, or operated by any state government agency.
Garden of Life LLC was the subject of a data breach notification filed with the NH Attorney General. The AG filing was recorded on January 17, 2025.
From the AG filing description
Garden of Life LLC is a well-known brand within the health and wellness sector, specializing in the direct-to-consumer distribution of organic nutritional supplements, vitamins, and whole-food products. To facilitate e-commerce operations, maintain customer loyalty programs, and manage direct shipping and fulfillment, the company routinely collects and stores extensive personal information from its customer base. This repository of consumer data typically includes sensitive payment details, detailed purchase and wellness preference histories, shipping addresses, email contacts, and account credentials, making the organization a high-value target for cybercriminals seeking monetizable consumer records. In 2025, Garden of Life LLC reported a significant data security incident to the New Hampshire Attorney General's office, alerting consumers and regulatory bodies to an unauthorized breach of its digital infrastructure. While the exact vectors of cyberattacks targeting e-commerce and retail supply chains frequently involve credential stuffing, third-party vendor compromises, or malware-based intrusions, incidents of this nature generally indicate that unauthorized actors bypassed existing network security controls. Such breaches often leave consumer databases exposed for extended periods before detection, allowing malicious entities to exfiltrate vast quantities of sensitive digital assets. The exposure resulting from the Garden of Life LLC breach puts affected consumers at immediate risk of identity theft, financial fraud, and targeted phishing campaigns. Compromised data types—such as full names, residential addresses, financial account details, and purchase histories—can be weaponized by cybercriminals to execute unauthorized transactions, open fraudulent lines of credit, or craft convincing social engineering attacks that impersonate the brand. Because purchase histories often reflect personal health and wellness priorities, the leaked data carries an added layer of sensitivity, laying bare intimate details of consumers' daily lives and consumption habits to malicious third parties. As an entity handling consumer data and processing online transactions, Garden of Life LLC was bound by established state and federal regulatory frameworks, including the Federal Trade Commission (FTC) Act, which mandates reasonable and appropriate data security practices. Corporations that collect personal and financial information have a legal duty to implement robust administrative, technical, and physical safeguards—such as multi-factor authentication, end-to-end encryption, and regular vulnerability assessments—to prevent unauthorized access. The occurrence of this data breach strongly suggests a potential failure in upholding these mandatory security standards, raising serious questions about the adequacy of the company's protective measures. Receiving an official data breach notification letter from Garden of Life LLC serves as formal acknowledgment that your private information was compromised due to corporate negligence, establishing the legal standing necessary to participate in a class action lawsuit. Affected individuals do not need to wait until they experience actual financial loss or identity theft to take legal action; the increased risk and the time required to monitor your accounts constitute legally compensable harms. Our firm is currently investigating potential claims on behalf of impacted consumers on a contingency fee basis, meaning you pay nothing out of pocket unless we successfully recover compensation on your behalf.
Under the New Hampshire data breach notification law, you may have a legal claim against Garden of Life LLC if any of the following apply:
Based on the data types reported in this filing:
Phone numbers exposed in breaches are used for SIM swapping attacks — hijacking your number to bypass two-factor authentication on financial accounts.
Common categories of compensation in data breach class actions
Courts recognize that the time spent monitoring accounts, placing credit freezes, and dealing with the aftermath of a breach has real economic value. This category of damages is recoverable even without direct financial loss.
Direct financial losses resulting from the breach — unauthorized charges, fraudulent transfers, or fees incurred through fraud — are recoverable as compensatory damages. Banks may reverse some charges; a class action recovers the remainder and associated costs.
When login credentials are exposed, the costs of downstream account compromises — password managers, security audits, and recovery costs for hijacked downstream accounts — can be recovered. Courts in recent class actions have awarded damages for credential exposure even without proven misuse.
Data breach victims regularly report anxiety, loss of sleep, and ongoing fear of identity theft. These non-economic harms are cognizable injuries in data breach litigation, particularly in cases involving SSN or medical record exposure.
Note: an attorney general breach filing does not by itself establish a settlement fund, a payment amount, or a claim deadline. If an official settlement notice is later issued, rely on that notice for payment details and deadlines.
No. Under New Hampshire data breach notification law and federal law, the unauthorized exposure of your personal data — regardless of whether it has been actively misused — can be sufficient grounds for a claim. The breach itself is the injury.
Nothing. The Law Office of David S. Harris handles data breach cases on contingency — you pay zero upfront and owe nothing unless compensation is recovered.
Banks may reverse fraudulent charges, but they are not obligated to compensate you for time lost, stress, or indirect damages. A class action claim against the breached company can recover those additional categories of harm.
Statutes of limitations for data breach claims vary by state but typically run 2–4 years. Depending on when you learned of the breach, you may still have time. Contact our office for a free eligibility review — there is no cost to find out.
Accepting free credit monitoring from Garden of Life LLC does not waive your right to pursue legal action unless you signed a specific release waiving claims. In most cases, victims who accepted monitoring can still file.
Not necessarily. Many data breach victims are never notified directly. If your personal information was held by Garden of Life LLC during the relevant period, you may still qualify even without receiving a letter. A free eligibility review can confirm your status.
Most data breach class actions resolve within 18 to 36 months, though timelines vary by court and complexity. Your participation requires minimal effort — typically completing a claim form. Our office handles all litigation; you are notified when a settlement is reached.
Applicable State Law
This breach was reported under the New Hampshire data breach notification law, which mandates notification and establishes your right to seek damages.
Garden of Life LLC breach?
Free case review · No fee unless you win