Brightline Apartments LLC
bd_bf99fc2a4df4a34d · schema v1 · pii pii-v1
Full breach record for Brightline Apartments LLC →Brightline, Inc., a virtual behavioral health provider, notified the California AG of a data breach affecting subscriber eligibility information. The incident stemmed from a third-party vendor, Fortra, whose GoAnywhere MFT service was compromised via a previously unknown vulnerability on January 30, 2023. Brightline became aware of the incident on February 4, 2023. Affected data included names, addresses, member IDs, dates of birth, phone numbers, and employer information. No SSNs, financial accounts, or medical records were involved. Brightline removed data from the service, implemented additional security measures, and offered 2 years of credit monitoring.
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_d59ed55c5ee4770aCalifornia State AGfiled 2023-05-12(5d gap)Verified
- bd_0868c3f9cf500602California State AGfiled 2023-05-10(7d gap)Verified
- bd_4c63e3855981b122HHS OCRfiled 2023-05-10(7d gap)Verified
- bd_b69375073a6e96d4Maine State AGfiled 2023-05-10(7d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 30d gap
- bd_f567c60a6fd57cc4HHS OCRfiled 2023-05-26(9d gap)Verified
- bd_163db05cc4cb8958Oregon State AGfiled 2023-05-02(15d gap)Verified
- bd_a1b16fb406ed3ce9California State AGfiled 2023-04-21(26d gap)Verified
- bd_a0176e4142b0a370HHS OCRfiled 2023-04-20(27d gap)Verified
- bd_5ea7d3fbb2a5464aVermont State AGfiled 2023-04-19(28d gap)Verified
- bd_ab681e087aaa2ef4New Hampshire State AGfiled 2023-04-17(30d gap)Verified
Showing first 10 of 23 linked disclosures.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-566866
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 17, 2023
- Raw hash
- 41e5dd022ed8d5aba6e1273a97e1448e3488ecccfa01458dc07931dfc41c920b
Reporting entity
- Name
- Brightline Apartments LLCnorm: brightline apartments
Victim entity
- Name
- Brightline Apartments LLCnorm: brightline apartments
Incident
- Discovered
- Feb 4, 2023
- Materiality determined
- —
- Notification sent
- Apr 7, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via Fortra
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 15 weeks(102 days from discovery to filing)
- Compliance flags
- CA 60-day late · 62d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 4, 2023→ Notified: Apr 7, 202362d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.