HackingCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
CROWN EQUIPMENT CORPORATION
bd_0b9529421edd36d4 · schema v1 · pii pii-v1
Full breach record for CROWN EQUIPMENT CORPORATION →Crown Equipment Corporation notified Vermont consumers of a June 9, 2024 cyberattack where unauthorized third parties accessed IT systems containing employee and family member data, including names, SSNs, driver's licenses, financial accounts, and health info. Crown contained the threat, engaged forensic investigators, notified federal law enforcement, and offered 24 months of credit monitoring.
Vermont clock⏱ VT AG >14 bday9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_865c226d1d559e29Maine State AGfiled 2024-08-12Candidate
- bd_db5e9bdf22f2bc87California State AGfiled 2024-08-12Verified
- bd_4151be7f6a17ab54Indiana State AGfiled 2024-08-09(3d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-08-12-crown-equipment-corporation-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 12, 2024
- Raw hash
- e1dda6262a778ec9eed457964a9fc63e3d5422286b441c4aa5c211fa36385f5f
Reporting entity
- Name
- CROWN EQUIPMENT CORPORATIONnorm: crown equipment
Victim entity
- Name
- CROWN EQUIPMENT CORPORATIONnorm: crown equipment
Incident
- Discovered
- Jun 9, 2024
- Materiality determined
- —
- Notification sent
- Aug 8, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- proactively notified federal law enforcement agenciesreceived support from federal law enforcement and their cybersecurity partners
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(64 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.