cgm
ent_b500d59f5702a29ad6ab117d
Disclosures
11
State AG · Leak Site · 8 jurisdictions
Incidents
3
filings grouped by incident
Max affected reported
279,063
as filed · State AG OR
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- cgm
- Normalized
- cgm— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (11)newest first
- ⛰️New Hampshire State AGas victim2024-02-14
CGM, Inc. reports a supplemental breach notification to New Hampshire. An unknown actor accessed the network on Dec 28, 2022. Initial notice was sent June 2023; supplemental notice sent Feb 14, 2024, to 4 additional residents (2 NH, 2 RI). Data involved likely includes PII/SSN. Credit monitoring offered. Investigation ongoing.
- 🦞Maine State AGas victim2024-02-14
CGM, Inc. experienced an external system breach on December 15, 2022, which was discovered on December 18, 2023. The breach affected 2 Maine residents, compromising their names and driver's license or non-driver identification card numbers. The company notified the affected individuals on February 14, 2024, and offered 12 months of complimentary credit monitoring services through Equifax.
- 🦬Montana State AGas victim2024-02-14
CGM, Inc reported a data breach to the Montana Attorney General. The breach was reported on 2024-02-14. The breach occurred from 12/15/2022 to 12/28/2023. 4 Montana residents were affected.
- 🐻California State AGas victim2024-02-14
CGM, Inc. reported a supplemental data breach notification to the California Attorney General. An unknown external actor accessed CGM's network between December 15 and December 28, 2022. The unauthorized access involved personal information including names and other data elements. CGM engaged third-party specialists, notified federal law enforcement, and is offering credit monitoring services to affected individuals. The incident has been contained.
- ⛰️New Hampshire State AGas victim2023-06-12
CGM, Inc. notified the New Hampshire Attorney General of a data event affecting 2 NH residents. Unauthorized access occurred between Dec 15-28, 2022. CGM engaged third-party specialists, notified federal law enforcement, and offered 1-year credit monitoring. Investigation was ongoing at time of filing.
- 🦫Oregon State AGas victim2023-06-07
CGM, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-06-07. The breach occurred during 12/15/2022 - 12/28/2022. The breach was discovered on 5/18/2023. 279,063 individuals were affected. Notice was sent on 6/7/2023.
- 🌲Washington State AGas victim2023-06-07
CGM, Inc., a business sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2022-12-28 and filed notice on 2023-06-07. 4,174 Washington residents were affected. 161 days elapsed between awareness and notification. 13 days to identify the breach. 0 days to contain the breach.
- 🍁Vermont State AGas victim2023-06-07
CGM, Inc. notified consumers of a data breach discovered on December 28, 2022, where an unknown actor accessed its network. The incident potentially exposed personal information including names and government identifiers (SSN, DOB) of customers participating in federal connectivity programs. CGM engaged forensic specialists, notified law enforcement, and offered credit monitoring. A specific count of 2,834 Rhode Island residents was noted in the attached notice.
- 🐻California State AGas victim2023-06-07
CGM, Inc. notified the California Attorney General of a data breach affecting personal information. The incident occurred between December 15 and December 28, 2022, with unusual activity observed on December 28, 2022. An unknown external actor accessed the network. Affected data includes names and potentially Social Security numbers (implied by credit monitoring offer and standard PII scope, though letter says '<<data elements>>' and 'name'). CGM contained the threat, engaged third-party specialists, notified federal law enforcement, and is offering credit monitoring. The notice specifically mentions approximately 2,834 Rhode Island residents may be impacted.
- 🦞Maine State AGas victim2023-06-07
CGM, Inc. experienced an external system breach that occurred on December 15, 2022, and was discovered on May 18, 2023. The breach compromised names combined with driver's license or non-driver identification card numbers. CGM notified affected individuals on June 7, 2023, and offered 12 months of complimentary credit monitoring services through TransUnion.
- GLOBALLeak Siteas victim2022-02-27