Recall Summary
| Recall number | None |
| Issued by | Issuing agency |
| Date | 2026-07-25 |
| Company | Fortra |
| Units affected | Not disclosed |
| Severity | Not classified |
Remedy: Follow the instructions in the official notice linked below. The agency record for this recall did not contain remedy text we could verify against this product, so we have not reproduced it here.
A fortra lawsuit filed in federal court in Alabama has put renewed attention on the long tail of legal fallout from the 2023 compromise of Fortra’s GoAnywhere managed file transfer software. As of today, the verified docket record reviewed for this article contains exactly one filing: Cooks v. Fortra Data Breach Litigation Settlement Administrator (MAG+), docketed in the United States District Court for the Middle District of Alabama on March 24, 2026.
- What the verified docket actually says
- Why the caption matters in this fortra lawsuit
- The underlying event these claims trace back to
- Who was affected
- What this kind of case typically alleges
- How the litigation is building
- What usually happens next procedurally
- Current status
- What to do now if you were affected
- Deadlines exist and they vary
- Practical protective steps
- Limits of this article
This article explains what that record shows, what it does not show, and what people affected by the underlying breach should be doing to protect their own interests.
Case Timeline
Last checked: July 26, 2026
- May 29, 2026 (Case Status): The settlement administrator mailed replacement checks to claimants whose digital payments failed or who elected paper checks, marking the distribution stage of the approved settlement. (Court Record)
- March 24, 2026 (Latest Activity): Newest lawsuit filed — Cooks v. Fortra Data Breach Litigation Settlement Administrator (MAG+), M. District of Alabama (Docket 2:26-cv-00205) (Court Record)
- September 17, 2025 (Settlement): Judge Ruiz entered an order granting final approval to the $20 million global settlement and awarding attorneys’ fees of up to 33% of the fund. (Court Record)
- April 18, 2025 (Settlement): Judge Ruiz granted preliminary approval to a $20 million global settlement resolving the consolidated Fortra file transfer breach claims against Fortra, NationsBenefits, Aetna, Community Health Systems, Imagine360, Intellihartx and other defendants. (Court Record)
- September 18, 2024 (Ruling): The MDL court granted in part and denied in part the NationsBenefits defendants’ motion to dismiss, sustaining dismissal of the contract and certain state statutory claims while allowing negligence and most consumer-protection claims to proceed into discovery. (Court Record)
- February 05, 2024 (Consolidation): The Judicial Panel on Multidistrict Litigation centralized the Fortra GoAnywhere data breach actions before Judge Rodolfo A. Ruiz II in the Southern District of Florida as MDL No. 3090. (Court Record)
What the verified docket actually says
The court record lists one case: Cooks v. Fortra Data Breach Litigation Settlement Administrator (MAG+), filed March 24, 2026, in the Middle District of Alabama, categorized on the docket sheet under the nature-of-suit code for Civil Rights: Other. The full public record is available through CourtListener’s docket for the case. That is the complete verified set — one filing, one court, one filing date. No other case numbers, plaintiffs, firms, or damages figures are established by this record.
Why the caption matters in this fortra lawsuit
The named defendant in this fortra lawsuit is the settlement administrator associated with the Fortra data breach litigation, not Fortra’s software business directly. Administrators are the third-party entities courts appoint to handle notice, claim intake, eligibility review, and distribution in consolidated data breach proceedings. Suits naming an administrator typically concern how a claim was received, processed, denied, or communicated, rather than the original security failure. The docket does not spell out the specific allegations, so nothing beyond the caption and filing data should be treated as established fact.
The underlying event these claims trace back to
The dispute sits downstream of a widely documented 2023 security incident. Attackers exploited CVE-2023-0669, a pre-authentication command injection flaw in the License Response Servlet of Fortra’s GoAnywhere MFT product, to run code on customer-hosted systems. Fortra published its own summary of the investigation related to CVE-2023-0669. Public reporting placed the initial unauthorized access window in late January 2023, with customer notification in early February and a patch shortly after.
Who was affected
Because GoAnywhere is business-to-business file transfer software, most affected individuals never used the product themselves. Their information moved through it because an employer, insurer, health system, benefits vendor, lender, or government contractor used GoAnywhere to move files. That indirect exposure is why notification letters often arrived from an organization people recognized rather than from Fortra. Anyone who received such a notice in 2023 or later is the population from which downstream claimants have generally emerged.
What this kind of case typically alleges
Speaking generally, and not as a description of this specific complaint, downstream data breach filings commonly allege inadequate safeguarding of personal information, delayed or insufficient notice, or failure to honor obligations owed to affected people. Filings that name an administrator instead of the breached company more often concern process: a claim treated as untimely, documentation deemed insufficient, or a benefit the claimant believes was mishandled. The single verified filing here has not been adjudicated, and nothing in the record establishes that any allegation is true.
📨 Get Free Mass Tort Guides Alerts
Free · No spam · Unsubscribe anytime
How the litigation is building
Litigation of this type tends to accumulate one filing at a time rather than arriving all at once. Individual people bring separate suits in their own districts, on their own timelines, over their own particular grievances. The pattern in breach-related disputes has been consistent: an initial wave against the breached entity, then a slower secondary wave of individual filings raising administration and process complaints. One verified filing is the current count in this docket set. That number can grow, and this fortra lawsuit may not remain the only one.
What usually happens next procedurally
After a complaint is docketed, the defendant must be served and then responds, often with a motion to dismiss testing whether the claims are legally sufficient. If the case survives, it moves into discovery, where both sides exchange documents and take testimony. Many disputes resolve before trial. When multiple similar suits accumulate across districts, parties sometimes ask for coordination so overlapping questions are handled once. None of those steps is guaranteed in any particular fortra lawsuit.
Current status
The verified status is straightforward: one case, filed March 24, 2026, pending in the Middle District of Alabama. The “MAG+” notation in the caption reflects magistrate judge involvement in case management. No outcome, ruling, or resolution is established by the record reviewed here. Anyone tracking developments should read the docket directly rather than relying on secondhand summaries, since docket entries update as the case proceeds.
What to do now if you were affected
Start with records. Keep the original breach notification letter, the envelope, and any correspondence about it. Save any claim confirmation numbers, submission receipts, email acknowledgments, and denial letters. Preserve documentation of any out-of-pocket costs you attribute to the incident, including credit monitoring receipts, bank statements showing disputed charges, and time logs for hours spent resolving problems. Organized contemporaneous records are far more useful than reconstructed recollections.
Deadlines exist and they vary
Time limits apply to claims of this kind, and they are not uniform. Statutes of limitations differ by state and by legal theory. Court-ordered deadlines in consolidated proceedings differ from those in an individually filed fortra lawsuit. Appeal windows and objection periods are short and strictly enforced. If a document you received lists a date, treat that date as real and act well before it. Do not assume a deadline you missed elsewhere has any bearing on a different proceeding.
Practical protective steps
Independent of any litigation, standard breach hygiene still applies. Review credit reports from all three bureaus, consider a credit freeze, monitor financial and medical statements for unfamiliar activity, and be alert to phishing that references the breach by name. Attackers frequently exploit breach publicity, and messages claiming to come from a court or administrator are a common lure. Verify contact details independently before responding to anything requesting personal or payment information.
Limits of this article
This is general legal information, not legal advice, and reading it creates no attorney-client relationship. It does not evaluate anyone’s individual situation, predict any outcome, or estimate any recovery. Every claim about litigation above traces to one verified docket entry. For advice about your circumstances, consult a licensed attorney in your jurisdiction, and bring your records with you.
Were You Injured by a Recalled Product?
A recall by itself is a safety action, not a legal claim. However, if a recalled product caused a real injury, you may be eligible to pursue compensation. A licensed attorney can review your situation at no upfront cost — most work on contingency, meaning you pay nothing unless you recover.
Official Sources & Resources
Verify every recall against the issuing agency before acting:
- the issuing agency: official recall database — the record of truth for this notice
- CPSC: cpsc.gov — household goods, toys, furniture, appliances
- FDA: fda.gov — food, drugs, and medical devices
- NHTSA: nhtsa.gov — vehicles, tires, and child car seats
- USDA FSIS: fsis.usda.gov — meat, poultry, and egg products
Content last reviewed July 2026. This is general educational information, not legal advice. If you notice outdated information, please contact us.
Related Guides
- All Product Recalls
- All Active MDL Cases
- Mass Tort Explainers
- Mass Tort Tips
- Tort Reform by State — 50-State Comparison
You May Also Like
Attorney Advertising. The information on this page is provided for general informational purposes only and does not constitute legal advice. A product recall is a safety action by a manufacturer or regulator and does not by itself establish liability or create a legal claim. No attorney-client relationship is created by accessing or using this content. Every case is unique. If you believe you were harmed by a recalled product, consult a licensed attorney in your jurisdiction.