HackingCustomer Data InvolvedIDENTITY_BASICLowContained
cgm
bd_edabe55eaf55e042 · schema v1 · pii pii-v1
Full breach record for cgm →CGM, Inc. reported a supplemental data breach notification to the California Attorney General. An unknown external actor accessed CGM's network between December 15 and December 28, 2022. The unauthorized access involved personal information including names and other data elements. CGM engaged third-party specialists, notified federal law enforcement, and is offering credit monitoring services to affected individuals. The incident has been contained.
Leak gap clock✗ Leak >180d14 months discovery → filing
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_17cf47586e44d973New Hampshire State AGfiled 2024-02-14Verified
- bd_6c91726908581280Montana State AGfiled 2024-02-14Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-581040
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 14, 2024
- Raw hash
- 3ad623a9ac99ccee5adc48f8eb31914f169d464793f72a1a3a265cb110818035
Reporting entity
- Name
- cgm
Victim entity
- Name
- cgm
Incident
- Discovered
- Dec 28, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unknown
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notifying relevant regulatory authorities, as required
Compliance
- Time to disclose
- 14 months(413 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.