TriWest reported that the attackers obtained sensitive information, including beneficiaries' names, DoD Benefits numbers, ZIP codes, authorization request types, and, in some cases, Social Security numbers, mailing addresses, and dates of birth (paragraph 4)