HackingVulnerability ExploitCapture Stored DataSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedDownstream VictimsIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Brightline Apartments LLC
bd_ab681e087aaa2ef4 · schema v1 · pii pii-v1
Full breach record for Brightline Apartments LLC →Brightline, Inc. notified the NH AG of a data breach involving its third-party vendor Fortra's GoAnywhere MFT SaaS. An unauthorized party exploited a previously unknown vulnerability to access accounts and download files starting Jan 30, 2023. Brightline learned of the incident on Feb 4, 2023. Approximately 180 NH residents were affected, with data including names, addresses, DOBs, member IDs, and some SSNs. Brightline engaged its incident response plan, retained counsel, and offered 2 years of credit monitoring.
This filing is one of 24 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_5ea7d3fbb2a5464aVermont State AGfiled 2023-04-19(2d gap)Verified
- bd_a0176e4142b0a370HHS OCRfiled 2023-04-20(3d gap)Verified
- bd_a1b16fb406ed3ce9California State AGfiled 2023-04-21(4d gap)Verified
- bd_163db05cc4cb8958Oregon State AGfiled 2023-05-02(15d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 39d gap
- bd_0868c3f9cf500602California State AGfiled 2023-05-10(23d gap)Verified
- bd_4c63e3855981b122HHS OCRfiled 2023-05-10(23d gap)Verified
- bd_b69375073a6e96d4Maine State AGfiled 2023-05-10(23d gap)Verified
- bd_d59ed55c5ee4770aCalifornia State AGfiled 2023-05-12(25d gap)Verified
- bd_bf99fc2a4df4a34dCalifornia State AGfiled 2023-05-17(30d gap)Verified
- bd_f567c60a6fd57cc4HHS OCRfiled 2023-05-26(39d gap)Verified
Showing first 10 of 23 linked disclosures.
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/brightline-20230417.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 17, 2023
- Raw hash
- 22fc8f13f4e2a97055821fc1d18559378d5bd18ce9fa0c3f2eb4b2607581e76a
Reporting entity
- Name
- Brightline Apartments LLCnorm: brightline apartments
Victim entity
- Name
- Brightline Apartments LLCnorm: brightline apartments
Incident
- Discovered
- Feb 4, 2023
- Materiality determined
- —
- Notification sent
- Apr 7, 2023
- Affected individuals
- 180
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Office of the Attorney General
- Third party
- via Fortra
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 10 weeks(72 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.