TGI Direct, Inc.
bd_06df0fe277351ecf · schema v1 · pii pii-v1
Full breach record for TGI Direct, Inc. →2 incidents on fileTGI Direct, Inc. disclosed a cybersecurity incident involving the MOVEit file transfer tool. On May 28, 2023, unauthorized access occurred via an exploited vulnerability. The breach exposed names, addresses, Member IDs, and medical/insurance information. TGI notified federal law enforcement, engaged third-party specialists, and applied security patches. Written notice was sent to 3,428 Washington residents on January 17, 2024, offering 12 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
May 28, 2023
Begins
May 28, 2023
Discovered
Jan 17, 2024
Filed
vs. sector median
+15 wks slower
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitecl0pbd_5a0a30a13f79c52a2023-07-12 · +189dVerified by operator
Regulatory filings (3) · sorted by filing gap
- HHS OCRbd_5aafe8f2b85da8222024-01-17Verified
- Montana State AGbd_009da678313b6f362023-11-21 · +57dVerified
- HHS OCRbd_7964b602f8ba8f0f2023-11-21 · +57dVerified
Filing propagation · 4 filings · 3 states
View merged incident ↗Pattern: first filing Nov 21 (MT), last Jan 17 (WA) — a 57-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.