Clustered 4 filings across 4 jurisdictions · filing window Jun 7, 2023 → Jun 12, 2023. View entity profile → Other incidents for this victim →
incident inc_8ff22da7b58a4cb6 · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Identity (basic) · Government ID
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
CA NH VT WA
all State AG
Earliest sighting first · deep chronology in Litigation Timeline
Dec 15, 2022 → Dec 28, 2022
When the intrusion reportedly occurred, per the linked filings
Dec 28, 2022
Reported by WASHINGTON AG, VERMONT AG, CALIFORNIA AG, NEW HAMPSHIRE AG filings
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
CGM, Inc., a business sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2022-12-28 and filed notice on 2023-06-07. 4,174 Washington residents were affected. 161 days elapsed between awareness and notification. 13 days to identify the breach. 0 days to contain the breach.
Affected (this filing): 4,174
CGM, Inc. notified consumers of a data breach discovered on December 28, 2022, where an unknown actor accessed its network. The incident potentially exposed personal information including names and government identifiers (SSN, DOB) of customers participating in federal connectivity programs. CGM engaged forensic specialists, notified law enforcement, and offered credit monitoring. A specific count of 2,834 Rhode Island residents was noted in the attached notice.
CGM, Inc. notified the California Attorney General of a data breach affecting personal information. The incident occurred between December 15 and December 28, 2022, with unusual activity observed on December 28, 2022. An unknown external actor accessed the network. Affected data includes names and potentially Social Security numbers (implied by credit monitoring offer and standard PII scope, though letter says '<<data elements>>' and 'name'). CGM contained the threat, engaged third-party specialists, notified federal law enforcement, and is offering credit monitoring. The notice specifically mentions approximately 2,834 Rhode Island residents may be impacted.
CGM, Inc. notified the New Hampshire Attorney General of a data event affecting 2 NH residents. Unauthorized access occurred between Dec 15-28, 2022. CGM engaged third-party specialists, notified federal law enforcement, and offered 1-year credit monitoring. Investigation was ongoing at time of filing.
Affected (this filing): 2