HackingVulnerability ExploitZero-DayData ExfiltratedSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
FORTRA, LLC
bd_5e724c809fdf07f5 · schema v1 · pii pii-v1
Full breach record for FORTRA, LLC →CHSPSC, LLC reported a security incident involving its third-party vendor Fortra, LLC. Fortra exploited a previously unknown vulnerability (zero-day) in its GoAnywhere file transfer platform between January 28-30, 2023. The incident resulted in the unauthorized disclosure of patient and employee data, including names, addresses, SSNs, and medical information. CHSPSC notified the Idaho Attorney General on March 8, 2023, offered 24 months of credit monitoring, and confirmed the incident was contained.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_e2b12c38a3b889c9Delaware State AGfiled 2023-03-06(2d gap)Candidate
- bd_4a2792be08f2ab41Idaho State AGfiled 2023-04-18(41d gap)Verified
Source provenance
- Source URL
- https://www.ag.idaho.gov/content/uploads/2023/03/3-8-2023-CHSPSC-LLC.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 8, 2023
- Raw hash
- 66a75148c69a5122c3eb57c8eb0038a3b8c9f0de619076dbc46459d9400f1917
Reporting entity
- Name
- CHSPSC, LLC - Updatednorm: chspsc llc updated
Victim entity
- Name
- FORTRA, LLCnorm: fortra
Incident
- Discovered
- Jan 30, 2023
- Materiality determined
- —
- Notification sent
- Mar 8, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1486 Data Encrypted for Impact
- Threat actor
- External
- Regulator citations
- Notified Idaho Attorney General’s Office Consumer Protection Division
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(37 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.