Brightline Apartments LLC
bd_954187ed06e346b7 · schema v1 · pii pii-v1
Full breach record for Brightline Apartments LLC →Brightline, Inc., a virtual behavioral health provider, notified affected individuals of a data security incident involving Fortra's GoAnywhere MFT SaaS, a third-party file transfer service. On January 30, 2023, Fortra discovered suspicious activity; an unauthorized party exploited a previously-unknown vulnerability to access customer accounts and download files. Brightline learned of the incident on February 4, 2023. Exposed data included names, addresses, member IDs, dates of birth, phone numbers, employer names, group IDs, coverage dates, and for some, Social Security numbers. Brightline responded by rebuilding infrastructure, restricting access, and offering 2 years of credit monitoring via Cyberscout.
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_5ea7d3fbb2a5464aVermont State AGfiled 2023-04-19(7d gap)Verified
- bd_a0176e4142b0a370HHS OCRfiled 2023-04-20(8d gap)Verified
- bd_a1b16fb406ed3ce9California State AGfiled 2023-04-21(9d gap)Verified
- bd_163db05cc4cb8958Oregon State AGfiled 2023-05-02(20d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 44d gap
- bd_0868c3f9cf500602California State AGfiled 2023-05-10(28d gap)Verified
- bd_4c63e3855981b122HHS OCRfiled 2023-05-10(28d gap)Verified
- bd_b69375073a6e96d4Maine State AGfiled 2023-05-10(28d gap)Verified
- bd_d59ed55c5ee4770aCalifornia State AGfiled 2023-05-12(30d gap)Verified
- bd_bf99fc2a4df4a34dCalifornia State AGfiled 2023-05-17(35d gap)Verified
- bd_f567c60a6fd57cc4HHS OCRfiled 2023-05-26(44d gap)Verified
Showing first 10 of 23 linked disclosures.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-565472
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 12, 2023
- Raw hash
- 15bd9c9f1917a5c377d89064be788087ddd28fa7d25831211758d54fb5a42d33
Reporting entity
- Name
- Brightline Apartments LLCnorm: brightline apartments
Victim entity
- Name
- Brightline Apartments LLCnorm: brightline apartments
- Industry
- HealthcarellmTechnologyllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Apr 7, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1530 Data from Cloud Storage Object
- Threat actor
- External
- Third party
- via Fortra (formerly HelpSystems)
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.