Brightline, Inc.
bd_19914189b0b36681 · schema v1 · pii pii-v1
Full breach record for Brightline, Inc. →4 incidents on fileBrightline, Inc. notified individuals of a data breach involving its third-party file transfer provider, Fortra. An unauthorized party exploited a vulnerability in Fortra's GoAnywhere MFT service on Jan 30, 2023, to access files containing demographic PII (name, address, DOB, member ID). Brightline was notified on Feb 4, 2023, and sent notices on Apr 7, 2023. No PHI or SSNs were involved. Credit monitoring offered.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 30, 2023
Begins
Feb 4, 2023
Discovered
Apr 19, 2023
Filed
vs. sector median
1 wks faster
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Idaho State AGbd_532b57f7fd2eedfb2023-05-30 · +41dVerified
- Illinois State AGbd_c10a34ae59efcae42023-01-01 · +108dCandidate
Filing propagation · 3 filings · 3 states
View merged incident ↗Pattern: first filing Jan 1 (IL), last May 30 (ID) — a 149-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.