FORTRA, LLC
bd_e2b12c38a3b889c9 · schema v1 · pii pii-v1
Full breach record for FORTRA, LLC →CHSPSC, LLC reported a security incident involving its third-party vendor Fortra, LLC, affecting the GoAnywhere file transfer platform. The incident occurred between January 28-30, 2023, involving exploitation of a previously unknown vulnerability (zero-day). Data disclosed included names, addresses, SSNs, DOBs, and medical/insurance information. Fortra contained the breach by taking systems offline, deleting attacker accounts, and issuing a patch. CHSPSC provided 24 months of credit monitoring and identity restoration services to affected individuals across multiple states.
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_5e724c809fdf07f5Idaho State AGfiled 2023-03-08(2d gap)Candidate
- bd_4a2792be08f2ab41Idaho State AGfiled 2023-04-18(43d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/03/Notice-of-Fortra-Data-Security-Incident.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 6, 2023
- Raw hash
- 6670616f1ebf6590b774cfde9b82407df636f16d905f01b3734ec091344ef791
Reporting entity
- Name
- CHSPSC, LLC - Updatednorm: chspsc llc updated
Victim entity
- Name
- FORTRA, LLCnorm: fortra
Incident
- Discovered
- Jan 30, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Contacted law enforcement, including the Federal Bureau of Investigation (“FBI”) and the Cybersecurity and Infrastructure Security Agency (“CISA”)
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(35 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.