
The Clop ransomware gang has apologised for targeting US-based pediatric behavioural and mental health care provider Brightline and says it has deleted data stolen from the company.Brightline admitted last week that it suffered a data breach after the infamous Clop ransomware gang exploited a zero-day vulnerability in Fortra’s GoAnywhere MFT file transfer application to target its network.In a data security incident notification posted on its website, Brightline said that on February 4, IT solutions provider Fortra informed it about the notorious Clop ransomware gang exploiting a previously-unknown vulnerability in the GoAnywhere MFT file transfer application. The security issue, identified by security researcher Brian Krebs, enabled threat actors to inject remote code in the company’s internal network.Soon after Fortra notified Brightline about the security incident, the healthcare provider immediately launched an investigation to understand the scope of the data breach.“We determined that the unauthorised party acquired certain files that were saved in the Fortra service. After making this determination, we immediately began to analyse the files to determine which individuals and data had been affected.“As part of that analysis, it was determined that those files contained a limited amount of protected health information,” the healthcare company said.According to Brightline’s investigation, the compromised information includes names, addresses, dates of birth, member identification numbers, date of health plan coverage, and employer names. The security incident also affected several other healthcare organisations with whom Brightline has partnered, including well-known organisations like Diageo, Nintendo of America Inc., Harvard University, Stanford University, and Boston Children’s Hospital.While the organisation did not mention the number of affected individuals in its data security incident notice, a filing with the U.S. Department of Health and Human Services confirms that at least 964,300 individuals have been affected by the data breach.“As soon as we became aware of the incident, we took immediate action to investigate it by confirming Fortra deactivated the unauthorised user’s credentials, turned off the service, and rebuilt our version so it was no longer vulnerable.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543