HackingVulnerability ExploitStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICPIILowContained
Brightline Apartments LLC
bd_fc57d126c7621e6e · schema v1 · pii pii-v1
Full breach record for Brightline Apartments LLC →Brightline, Inc. notified consumers of a data breach involving its third-party file transfer provider, Fortra. An unauthorized party exploited a previously unknown vulnerability in Fortra's GoAnywhere MFT service on Jan 30, 2023, to access files containing demographic PII (name, address, DOB, member ID) of Brightline plan enrollees. No SSNs or financial data were compromised. Brightline engaged cyber counsel and offered 2 years of credit monitoring via Cyberscout.
Vermont clock⏱ VT AG >14 bday9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 24 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_5ea7d3fbb2a5464aVermont State AGfiled 2023-04-19(12d gap)Verified
- bd_a0176e4142b0a370HHS OCRfiled 2023-04-20(13d gap)Verified
- bd_a1b16fb406ed3ce9California State AGfiled 2023-04-21(14d gap)Verified
- bd_163db05cc4cb8958Oregon State AGfiled 2023-05-02(25d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 49d gap
- bd_0868c3f9cf500602California State AGfiled 2023-05-10(33d gap)Verified
- bd_4c63e3855981b122HHS OCRfiled 2023-05-10(33d gap)Verified
- bd_b69375073a6e96d4Maine State AGfiled 2023-05-10(33d gap)Verified
- bd_d59ed55c5ee4770aCalifornia State AGfiled 2023-05-12(35d gap)Verified
- bd_bf99fc2a4df4a34dCalifornia State AGfiled 2023-05-17(40d gap)Verified
- bd_f567c60a6fd57cc4HHS OCRfiled 2023-05-26(49d gap)Verified
Showing first 10 of 23 linked disclosures.
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-04-07-brightline-fortra-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 7, 2023
- Raw hash
- 3f8ccf517561439ee0036e6169ce4bcb217cf4f3f630e43f734ccf54c73f3119
Reporting entity
- Name
- Brightline Apartments LLCnorm: brightline apartments
Victim entity
- Name
- Brightline Apartments LLCnorm: brightline apartments
Incident
- Discovered
- Feb 4, 2023
- Materiality determined
- —
- Notification sent
- Apr 7, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Fortra promptly notified law enforcement and is cooperating with their investigation
- Third party
- via Fortra
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(62 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.