HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTEMPLOYMENTMediumContained
Brightline Apartments LLC
bd_5ea7d3fbb2a5464a · schema v1 · pii pii-v1
Full breach record for Brightline Apartments LLC →Brightline, Inc. notified consumers of a data breach involving its third-party file transfer provider, Fortra (GoAnywhere MFT SaaS). The incident, occurring around Jan 30, 2023, exploited a vulnerability to access accounts. Affected data included names, DOB, SSN, and employment info. Brightline disabled access, removed data, and offered 2 years of credit monitoring.
Vermont clock✗ VT AG >45 bday11 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 24 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_a0176e4142b0a370HHS OCRfiled 2023-04-20(1d gap)Verified
- bd_a1b16fb406ed3ce9California State AGfiled 2023-04-21(2d gap)Verified
- bd_ab681e087aaa2ef4New Hampshire State AGfiled 2023-04-17(2d gap)Verified
- bd_163db05cc4cb8958Oregon State AGfiled 2023-05-02(13d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 37d gap
- bd_0868c3f9cf500602California State AGfiled 2023-05-10(21d gap)Verified
- bd_4c63e3855981b122HHS OCRfiled 2023-05-10(21d gap)Verified
- bd_b69375073a6e96d4Maine State AGfiled 2023-05-10(21d gap)Verified
- bd_d59ed55c5ee4770aCalifornia State AGfiled 2023-05-12(23d gap)Verified
- bd_bf99fc2a4df4a34dCalifornia State AGfiled 2023-05-17(28d gap)Verified
- bd_f567c60a6fd57cc4HHS OCRfiled 2023-05-26(37d gap)Verified
Showing first 10 of 23 linked disclosures.
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-04-19-brightline-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 19, 2023
- Raw hash
- 068c0182bb2f1321e311e1fafbb072c124641d991e7dbf800deb779341ab27f5
Reporting entity
- Name
- Brightline Apartments LLCnorm: brightline apartments
Victim entity
- Name
- Brightline Apartments LLCnorm: brightline apartments
Incident
- Discovered
- Feb 4, 2023
- Materiality determined
- —
- Notification sent
- Apr 19, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTEMPLOYMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Fortra notified law enforcement and we understand it is cooperating with their investigation of the GoAnywhere incident
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(74 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.