HackingVulnerability ExploitCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
CrossCheck, Inc.
bd_0b206ed1409f1b92 · schema v1 · pii pii-v1
Full breach record for CrossCheck, Inc. →CrossCheck, Inc. notified the Maryland Attorney General of a data incident occurring between May 18 and May 20, 2024. An unauthorized actor accessed the company's merchant portal, exposing the name and driver's license number of one Maryland resident. CrossCheck notified federal law enforcement, provided 12 months of complimentary credit monitoring via Experian, and issued individual notices on January 7, 2025.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376132.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 13, 2025
- Raw hash
- 2d151ff4b173da1e494394ce362cf94267c11bad7605ad76eb67105e36087fda
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- CrossCheck, Inc.norm: crosscheck
Incident
- Discovered
- May 20, 2024
- Materiality determined
- —
- Notification sent
- Jan 7, 2025
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 18 months(542 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.