Brightline Apartments LLC
bd_a1b16fb406ed3ce9 · schema v1 · pii pii-v1
Full breach record for Brightline Apartments LLC →Brightline, Inc. notified the California AG of a data breach involving a third-party vendor, Fortra (GoAnywhere MFT). An unauthorized party exploited a previously unknown vulnerability in Fortra's SaaS to access and download files containing personal information of Stanford group health plan members. Affected data includes names, addresses, DOBs, phone numbers, member IDs, employer names, and coverage dates. Brightline deactivated credentials, rebuilt infrastructure, and removed data from the affected service. Identity theft protection services were offered.
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_a0176e4142b0a370HHS OCRfiled 2023-04-20(1d gap)Verified
- bd_5ea7d3fbb2a5464aVermont State AGfiled 2023-04-19(2d gap)Verified
- bd_ab681e087aaa2ef4New Hampshire State AGfiled 2023-04-17(4d gap)Verified
- bd_163db05cc4cb8958Oregon State AGfiled 2023-05-02(11d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 35d gap
- bd_0868c3f9cf500602California State AGfiled 2023-05-10(19d gap)Verified
- bd_4c63e3855981b122HHS OCRfiled 2023-05-10(19d gap)Verified
- bd_b69375073a6e96d4Maine State AGfiled 2023-05-10(19d gap)Verified
- bd_d59ed55c5ee4770aCalifornia State AGfiled 2023-05-12(21d gap)Verified
- bd_bf99fc2a4df4a34dCalifornia State AGfiled 2023-05-17(26d gap)Verified
- bd_f567c60a6fd57cc4HHS OCRfiled 2023-05-26(35d gap)Verified
Showing first 10 of 23 linked disclosures.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-565859
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 21, 2023
- Raw hash
- b2d18f61ff962fe7c1c78959baee7672d10fe8d070fcfbbf72a6738fb63ebaf8
Reporting entity
- Name
- Brightline Apartments LLCnorm: brightline apartments
Victim entity
- Name
- Brightline Apartments LLCnorm: brightline apartments
Incident
- Discovered
- Feb 4, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICEMPLOYMENTHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via Fortra
- Initial access
- supply_chain
Compliance
- Time to disclose
- 11 weeks(76 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.