Confirmed breach. Intrusion Dec 15, 2022–Dec 28, 2022, discovered May 18, 2023 — the first regulatory filing landed 20 days later (flagged late). 279,064 individuals reported across the linked filings.
CGM, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-06-07. The breach occurred during 12/15/2022 - 12/28/2022. The breach was discovered on 5/18/2023. 279,063 individuals were affected. Notice was sent on 6/7/2023.
CGM, Inc. experienced an external system breach that occurred on December 15, 2022, and was discovered on May 18, 2023. The breach compromised names combined with driver's license or non-driver identification card numbers. CGM notified affected individuals on June 7, 2023, and offered 12 months of complimentary credit monitoring services through TransUnion.
Affected (this filing): 1
Leak >180d
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.