ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Clop ransomware gang deletes data stolen from pediatrics care provider Brightline

The Clop ransomware gang has apologised for targeting US-based pediatric behavioural and mental health care provider Brightline and says it has deleted data stolen from the company.Brightline admitted last week that it suffered a data breach after the infamous Clop ransomware gang exploited a zero-day vulnerability in Fortra’s GoAnywhere MFT file transfer application to target its network.In a data security incident notification posted on its website, Brightline said that on February 4, IT solutions provider Fortra informed it about the notorious Clop ransomware gang exploiting a previously-unknown vulnerability in the GoAnywhere MFT file transfer application. The security issue, identified by security researcher Brian Krebs, enabled threat actors to inject remote code in the company’s internal network.Soon after Fortra notified Brightline about the security incident, the healthcare provider immediately launched an investigation to understand the scope of the data breach.“We determined that the unauthorised party acquired certain files that were saved in the Fortra service. After making this determination, we immediately began to analyse the files to determine which individuals and data had been affected.“As part of that analysis, it was determined that those files contained a limited amount of protected health information,” the healthcare company said.According to Brightline’s investigation, the compromised information includes names, addresses, dates of birth, member identification numbers, date of health plan coverage, and employer names. The security incident also affected several other healthcare organisations with whom Brightline has partnered, including well-known organisations like Diageo, Nintendo of America Inc., Harvard University, Stanford University, and Boston Children’s Hospital.While the organisation did not mention the number of affected individuals in its data security incident notice, a filing with the U.S. Department of Health and Human Services confirms that at least 964,300 individuals have been affected by the data breach.“As soon as we became aware of the incident, we took immediate action to investigate it by confirming Fortra deactivated the unauthorised user’s credentials, turned off the service, and rebuilt our version so it was no longer vulnerable.  

 
“Further, we implemented additional security measures, including limiting ongoing access to verified users, removing all of our data from the service, and continuing ongoing measures to reduce data exposure until an alternative file transfer solution is identified and implemented,” Brightline explained.The company has offered two years of complimentary identity theft and credit monitoring services by Cyberscout to all affected individuals and has set up a dedicated hotline to answer all queries pertaining to the security incident.After the story came to light, the Clop ransomware gang contacted BleepingComputer to apologize for the incident and said that it deleted the data stolen from the healthcare provider.“We delete the data and we did not know what this company is doing, because not all companies are analysing. And we ask for forgiveness for this incident,” Clop told BleepingComputer in an email. While the authenticity of the ransomware gang’s claims can’t be verified, BleepingComputer confirmed that Brightline has been removed from the data leak site of the Clop ransomware gang.

Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543