TGI Direct, Inc.
bd_009da678313b6f36 · schema v1 · pii pii-v1
Full breach record for TGI Direct, Inc. →2 incidents on fileTGI Direct, Inc. notified individuals of a breach involving its MOVEit file transfer tool. An unauthorized actor exploited vulnerabilities in the software on May 28, 2023, accessing personal and protected health information for less than four hours. TGI secured its environment, applied patches, and engaged third-party specialists. Notices were sent on November 21, 2023, offering 24 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
May 28, 2023
Begins
May 28, 2023
Discovered
Nov 21, 2023
Filed
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitecl0pbd_5a0a30a13f79c52a2023-07-12 · +132dVerified by operator
Regulatory filings (3) · sorted by filing gap
- HHS OCRbd_7964b602f8ba8f0f2023-11-21Verified
- Washington State AGbd_06df0fe277351ecf2024-01-17 · +57dVerified
- HHS OCRbd_5aafe8f2b85da8222024-01-17 · +57dVerified
Filing propagation · 4 filings · 3 states
View merged incident ↗Pattern: first filing Nov 21 (MI), last Jan 17 (MI) — a 57-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.