HackingVulnerability ExploitData MishandlingSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedZero-DayIDENTITY_BASICIDENTITY_GOVERNMENTEMPLOYMENTMediumContained
Brightline Apartments LLC
bd_0868c3f9cf500602 · schema v1 · pii pii-v1
Full breach record for Brightline Apartments LLC →Brightline, Inc. notified the California AG of a data breach involving its third-party provider Fortra (GoAnywhere MFT SaaS). An unauthorized party exploited a previously unknown vulnerability on Jan 30, 2023, to access accounts and download files. Brightline became aware on Feb 4, 2023. Affected data includes names, DOB, SSN, and employment info for HP employees. No clinical data or financial accounts were involved. Brightline rebuilt infrastructure, removed data from the service, and offered 2 years of credit monitoring.
This filing is one of 24 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_4c63e3855981b122HHS OCRfiled 2023-05-10Verified
- bd_b69375073a6e96d4Maine State AGfiled 2023-05-10Verified
- bd_d59ed55c5ee4770aCalifornia State AGfiled 2023-05-12(2d gap)Verified
- bd_bf99fc2a4df4a34dCalifornia State AGfiled 2023-05-17(7d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 23d gap
- bd_163db05cc4cb8958Oregon State AGfiled 2023-05-02(8d gap)Verified
- bd_f567c60a6fd57cc4HHS OCRfiled 2023-05-26(16d gap)Verified
- bd_a1b16fb406ed3ce9California State AGfiled 2023-04-21(19d gap)Verified
- bd_a0176e4142b0a370HHS OCRfiled 2023-04-20(20d gap)Verified
- bd_5ea7d3fbb2a5464aVermont State AGfiled 2023-04-19(21d gap)Verified
- bd_ab681e087aaa2ef4New Hampshire State AGfiled 2023-04-17(23d gap)Verified
Showing first 10 of 23 linked disclosures.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-566585
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 10, 2023
- Raw hash
- 789b77d58f74f2bd5a2c9fd197960a8336d9ee758ae6c05647627225aebbfecc
Reporting entity
- Name
- Brightline Apartments LLCnorm: brightline apartments
Victim entity
- Name
- Brightline Apartments LLCnorm: brightline apartments
Incident
- Discovered
- Feb 4, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTEMPLOYMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via Fortra (formerly HelpSystems)
- Initial access
- supply_chain
Compliance
- Time to disclose
- 14 weeks(95 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.