FORTRA, LLC
ent_019e616b1ba480f1a4fc521c98478631
Disclosures
5
State AG · 2 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
11,173,555
as filed · State AG ID
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- FORTRA, LLC
- Normalized
- fortra— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5493004XPMXL46FKLN63
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- 💎Delaware State AGas victim2023-09-22
CHSPSC, LLC reported a security incident involving its third-party vendor Fortra, LLC, affecting the GoAnywhere file transfer platform. The incident occurred between January 28-30, 2023, exploiting a previously unknown vulnerability (zero-day). Personal information of patients from Community Health Systems affiliates was disclosed, including names, SSNs, DOBs, and medical/financial data. CHSPSC and Fortra engaged the FBI and CISA, took systems offline, patched the software, and offered 24 months of credit monitoring.
- 🥔Idaho State AGas victim2023-09-21
Fortra, LLC, a cybersecurity services provider, experienced a data incident impacting 1,202,699 individuals, including 96 Idaho residents. CHSPSC, LLC, Fortra's client, filed this addendum with the Idaho Attorney General. The investigation was ongoing, but notification notices were mailed to all affected individuals.
- 🥔Idaho State AGas victim2023-04-18
CHSPSC, LLC reported an addendum to a data incident involving its vendor, Fortra, LLC. Fortra's GoAnywhere file transfer platform was compromised via a previously unknown vulnerability (zero-day) between Jan 28-30, 2023. The incident exposed personal information of approximately 11.1 million individuals, including names, SSNs, DOBs, and medical/insurance data. CHSPSC notified the Idaho Attorney General, FBI, and CISA, and offered 24 months of credit monitoring via Experian.
- 🥔Idaho State AGas victim2023-03-08
CHSPSC, LLC reported a security incident involving its third-party vendor Fortra, LLC. Fortra exploited a previously unknown vulnerability (zero-day) in its GoAnywhere file transfer platform between January 28-30, 2023. The incident resulted in the unauthorized disclosure of patient and employee data, including names, addresses, SSNs, and medical information. CHSPSC notified the Idaho Attorney General on March 8, 2023, offered 24 months of credit monitoring, and confirmed the incident was contained.
- 💎Delaware State AGas victim2023-03-06
CHSPSC, LLC reported a security incident involving its third-party vendor Fortra, LLC, affecting the GoAnywhere file transfer platform. The incident occurred between January 28-30, 2023, involving exploitation of a previously unknown vulnerability (zero-day). Data disclosed included names, addresses, SSNs, DOBs, and medical/insurance information. Fortra contained the breach by taking systems offline, deleting attacker accounts, and issuing a patch. CHSPSC provided 24 months of credit monitoring and identity restoration services to affected individuals across multiple states.