Scrubs & Beyond (Kindthread) Data Breach

301 Scrubs Investors, LLC — doing business as Scrubs & Beyond and Kindthread — sent breach notification letters after identifying an incident with breach dates reported as June 6, 2024 and June 9, 2024. The letter provided to BreachLetter does not spell out exactly how the incident occurred, so the attack vector is currently listed as unknown, and it does not name a specific third party as the source of the breach. What the company does make clear is that it is offering free credit monitoring and identity protection services, a step companies typically take when sensitive personal information may have been involved.

The notification does not include an aggregate count of how many people were notified overall. It does specify that at least one Rhode Island resident was affected, and the letter includes state-specific notices for residents of Maryland, New York, New Mexico, North Carolina, Rhode Island, and Washington, D.C., suggesting the mailing went out broadly across multiple states.

What information was exposed?
  • The letter text supplied to BreachLetter does not list the specific categories of personal information involved in this incident.
  • The company is offering credit monitoring and identity protection services, which typically signals that some form of sensitive personal information may have been part of the exposure.
  • If you received a letter directly from Kindthread, check it for a specific list of data types — some notification letters include this detail in a section not captured here.

Kindthread is offering complimentary credit monitoring and identity protection services through Cyberscout. You can enroll at https://bfs.cyberscout.com/activate using the unique code printed in your individual letter, and you must enroll within 90 days from the date of the letter.

What should you do now?
  • Enroll in the free credit monitoring offered by Kindthread before the 90-day deadline listed in your letter, using the activation code included in your copy.
  • Request your free annual credit reports from TransUnion, Experian, and Equifax at annualcreditreport.com and review them for accounts or inquiries you don’t recognize.
  • Consider placing a fraud alert (free, lasts one year) or a credit freeze (free, blocks new credit in your name) with each of the three credit bureaus listed in your letter.
  • Watch your bank and credit card statements, as well as any explanation of benefits forms from insurers, for charges or activity you didn’t authorize.
  • Since the exact data exposed wasn’t detailed in this letter, treat any unexpected calls, emails, or account requests with extra caution, and consider signing up for a service like Aura or LifeLock, which can alert you if your information appears elsewhere.
  • Keep a copy of your notification letter and any enrollment confirmation in case you need to reference them later.

If you have questions, Kindthread can be reached at 1-833-799-2825 (8 a.m.–8 p.m. Eastern, excluding major U.S. holidays) or by writing to 1950 W. Corporate Way, PMB 79576, Anaheim, CA 92801.

Leave a Comment