Berkeley Research Group, LLC (BRG) reported a data breach that began on February 28, 2025, and was discovered on March 2, 2025. The incident involved unauthorized access to their network.
This breach affected over 110,000 individuals, including clients of BlueCross BlueShield of Tennessee, the UT System, TRICARE beneficiaries, and others. Exposed data types include names, Social Security numbers, dates of birth, addresses, tax IDs, financial and bank account information (some with PINs or passwords), medical information, health insurance details, government IDs (passports, driver’s licenses), and payment card details. BRG serves as a vendor for various clients, making this a third-party breach. While individual notification letters were sent starting in October 2025, the full extent of affected individuals and specific data types for all victims remains unclear.
Details can still emerge, and additional notifications may be delayed.