FORTRA, LLC
bd_5e724c809fdf07f5 · schema v1 · pii pii-v1
Full breach record for FORTRA, LLC →2 incidents on fileCHSPSC, LLC reported a security incident involving its third-party vendor Fortra, LLC. Fortra exploited a previously unknown vulnerability (zero-day) in its GoAnywhere file transfer platform between January 28-30, 2023. The incident resulted in the unauthorized disclosure of patient and employee data, including names, addresses, SSNs, and medical information. CHSPSC notified the Idaho Attorney General on March 8, 2023, offered 24 months of credit monitoring, and confirmed the incident was contained.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 28, 2023
Begins
Jan 30, 2023
Discovered
Mar 8, 2023
Filed
vs. sector median
7 wks faster
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Delaware State AGbd_e2b12c38a3b889c92023-03-06 · +2dCandidate
- Indiana State AGbd_ff546532f766e7fb2023-01-31 · +36dVerified
- Idaho State AGbd_4a2792be08f2ab412023-04-18 · +41dVerified
Filing propagation · 4 filings · 3 states
View merged incident ↗Pattern: first filing Jan 31 (IN), last Apr 18 (ID) — a 77-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.