cgm
bd_acd5ed6139e7a5a2 · schema v1 · pii pii-v1
Full breach record for cgm →3 incidents on fileCGM, Inc. notified the California Attorney General of a data breach affecting personal information. The incident occurred between December 15 and December 28, 2022, with unusual activity observed on December 28, 2022. An unknown external actor accessed the network. Affected data includes names and potentially Social Security numbers (implied by credit monitoring offer and standard PII scope, though letter says '<<data elements>>' and 'name'). CGM contained the threat, engaged third-party specialists, notified federal law enforcement, and is offering credit monitoring. The notice specifically mentions approximately 2,834 Rhode Island residents may be impacted.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 15, 2022
Begins
Dec 28, 2022
Discovered
Jun 7, 2023
Filed
vs. sector median
+4 wks slower
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- Oregon State AGbd_1a2025acb7c94a972023-06-07Verified
- Washington State AGbd_2735fea22890668d2023-06-07Verified
- Indiana State AGbd_5c2b629e07a673442023-06-07Verified
- Vermont State AGbd_a22f66366c7582892023-06-07Verified
Show 6 more filings ↓Show fewer ↑up to 253d gap
- Maine State AGbd_c89272bb6194d4ae2023-06-07Candidate
- New Hampshire State AGbd_51a69c1950f8dead2023-06-12 · +5dVerified
- New Hampshire State AGbd_17cf47586e44d9732024-02-14 · +252dVerified
- Montana State AGbd_6c917269085812802024-02-14 · +252dVerified
- California State AGbd_edabe55eaf55e0422024-02-14 · +252dVerified
- South Carolina State AGbd_59bc55eb0803b05c2024-02-15 · +253dVerified
Showing first 10 of 13 linked disclosures.
Filing propagation · 11 filings · 9 states
View merged incident ↗Pattern: first filing Jun 7 (OR), last Feb 15 (SC) — a 253-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Cascade drawn from the first 10 linked disclosures of 13 — the full spread may be wider.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.