MalwareRansomwareData EncryptedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSHEALTH_BASICEMPLOYMENTMediumContained
Crossroads Equipment Lease & Finance, LLC
bd_1ea0de9dca288ec8 · schema v1 · pii pii-v1
Full breach record for Crossroads Equipment Lease & Finance, LLC →Crossroads Equipment Lease & Finance, LLC experienced a ransomware attack on April 1, 2023, which encrypted computer systems and disrupted business functions. The company became aware of the incident on April 2, 2023. Personal information potentially compromised includes names, addresses, SSNs, government IDs, financial account details, and medical information. The company secured systems, migrated data to a cloud server, implemented MFA, and notified the FBI. Two years of credit monitoring are offered to affected customers.
California clockDiscovered Apr 2, 2023 → Notified Feb 23, 2024327d ✗ CA 60-day late47 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_0ad92da3eea5bc49New Hampshire State AGfiled 2024-02-23Verified
- bd_2a188244340d6000Indiana State AGfiled 2024-02-23Verified
- bd_7db02c0700987958Maine State AGfiled 2024-02-23Candidate
- bd_c00cbc9e0bd76d10Montana State AGfiled 2024-02-23Verified
Show 2 more filings ↓Show fewer ↑up to 102d gap
- bd_cebd1151800de2a6Vermont State AGfiled 2024-02-23Verified
- bd_2ecc67df1c6bd825California State AGfiled 2024-06-04(102d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-581427
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 23, 2024
- Raw hash
- c2ec9d9da94025b3b98c91cc4494d91fda7e39f02cf915597bc00f5a2bda326d
Reporting entity
- Name
- Crossroads Equipment Lease & Finance, LLCnorm: crossroads equipment lease finance
Victim entity
- Name
- Crossroads Equipment Lease & Finance, LLCnorm: crossroads equipment lease finance
Incident
- Discovered
- Apr 2, 2023
- Materiality determined
- —
- Notification sent
- Feb 23, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSHEALTH_BASICEMPLOYMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the Federal Bureau of Investigation
Compliance
- Time to disclose
- 47 weeks(327 days from discovery to filing)
- Compliance flags
- CA 60-day late · 327d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 2, 2023→ Notified: Feb 23, 2024327d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.