Brightline-Datenverletzung betrifft 783K pädiatrische Psychiatriepatienten

Teilen:

Pediatric mental health provider Brightline is warning patients that it suffered a data breach impacting 783,606 people after a ransomware gang stole data using a zero-day vulnerability in its Fortra GoAnywhere MFT secure file-sharing platform.

Brightline is a mental and behavioral health provider offering virtual counseling for children, teenagers, and their families.

In a new ‘data security notice’ displayed on the company’s website, Brightline confirmed that data was stolen from its GoAnywhere MFT service that contained protected health information.

These attacks were conducted by the Clop ransomware gang, who utilized a zero-day vulnerability tracked as CVE-2023-0669 to allegedly steal data from 130 companies.

According to Fortra’s latest update on its investigation, the threat actors began leveraging this vulnerability since January 18th, 2023.

Brightline was listed on Clop’s extortion portal on March 16th, 2023, indicating that the health startup was among the firms the ransomware actors breached in their large-scale attack.

The company’s internal investigation revealed that the data stolen by the Clop ransomware gang included the following personal information:

  • Full names
  • Physical addresses
  • Dates of birth
  • Member identification numbers
  • Date of health plan coverage
  • Employer names

The notice clarifies that Aetna member IDs have not been compromised due to this incident.

“As soon as we became aware of the incident, we took immediate action to investigate it by confirming Fortra deactivated the unauthorized user’s credentials, turned off the service, and rebuilt our version so it was no longer vulnerable,” reads Brightline’s security notice.

“Further, we implemented additional security measures, including limiting ongoing access to verified users, removing all of our data from the service, and continuing ongoing measures to reduce data exposure until an alternative file transfer solution is identified and implemented.”

Brightline’s extensive partnerships with healthcare institutes and companies in the U.S. has resulted in a security incident impacting many entities. This includes well-known organizations like Diageo, Nintendo of America Inc., Harvard University, Stanford University, and Boston Children’s Hospital.

The complete list of impacted entities can be found here.

Data published today on the breach portal of the U.S. Department of Health and Human Services indicates that the incident has impacted a total of 783,606 people.

However, this figure may increase as internal investigations progress. Brightline only submitted eight individual entries on the government portal, presumably corresponding to eight affected entities, but its website lists a more significant number of impacted organizations.

Brightline offers all impacted individuals two years of complimentary identity theft and credit monitoring services via Cyberscout.

Update 5/3/23: After the publication of this article, the Cl0p ransomware operation emailed BleepingComputer to say they deleted Brightline’s data from their data leak site.

“We delete the data and we did not know what this company is doing, because not all companies are analyzing. And we ask for forgiveness for this incident,” Clop emailed BleepingComputer.

While we have no way determining if they actually deleted all of the data in their possession, BleepingComputer can confirm that Brightline is no longer listed on the gang’s data leak site.

 

(c) Bill Toulas

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
6:23 am, Juli 13, 2025
Wetter-Symbol 15°C
L: 14° | H: 16°
klarer Himmel
Luftfeuchtigkeit: 88 %
Druck: 1013 mb
Wind: 3 mph E
Windböe: 7 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 9%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:58 am
Sonnenuntergang: 9:13 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
14° | 16°°C 0 mm 0% 6 mph 88 % 1013 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
19° | 27°°C 0 mm 0% 15 mph 72 % 1015 mb 0 mm/h
Di. Juli 15 10:00 pm
Wetter-Symbol
15° | 22°°C 0.94 mm 94% 15 mph 79 % 1016 mb 0 mm/h
Mi. Juli 16 10:00 pm
Wetter-Symbol
15° | 26°°C 0.4 mm 40% 13 mph 90 % 1016 mb 0 mm/h
Do. Juli 17 10:00 pm
Wetter-Symbol
19° | 25°°C 0 mm 0% 7 mph 61 % 1018 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
15° | 16°°C 0 mm 0% 5 mph 88 % 1013 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
18° | 23°°C 0 mm 0% 4 mph 77 % 1013 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
24° | 28°°C 0 mm 0% 3 mph 54 % 1012 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
30° | 30°°C 0 mm 0% 2 mph 30 % 1010 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
28° | 28°°C 0 mm 0% 4 mph 31 % 1009 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
23° | 23°°C 0 mm 0% 6 mph 47 % 1010 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
21° | 21°°C 0 mm 0% 5 mph 52 % 1011 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
20° | 20°°C 0 mm 0% 6 mph 61 % 1010 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€100,877.14
0.26%
Ethereum(ETH)
€2,532.20
0.38%
XRP(XRP)
€2.38
0.50%
Fesseln(USDT)
€0.86
-0.01%
Solana(SOL)
€138.65
-0.26%
USDC(USDC)
€0.86
0.00%
Dogecoin(DOGE)
€0.170139
-0.90%
Shiba Inu(SHIB)
€0.000011
0.20%
Pepe(PEPE)
€0.000010
1.22%
Peanut das Eichhörnchen(PNUT)
€0.246209
7.19%
Nach oben scrollen