MalwareRansomwareData EncryptedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSHEALTH_BASICEMPLOYMENTIPMediumContained
Crossroads Equipment Lease & Finance, LLC
bd_2ecc67df1c6bd825 · schema v1 · pii pii-v1
Full breach record for Crossroads Equipment Lease & Finance, LLC →Crossroads Equipment Lease & Finance, LLC experienced a ransomware attack on April 1, 2023, which encrypted its computer systems. The company became aware of the incident on April 2, 2023. Personal information potentially compromised includes names, addresses, SSNs, financial account details, and medical information. The company secured systems, migrated to a cloud server, implemented MFA, and notified the FBI. Credit monitoring is offered to affected customers.
California clockDiscovered Apr 2, 2023 → Notified Jun 3, 2024428d ✗ CA 60-day late14 months discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_0ad92da3eea5bc49New Hampshire State AGfiled 2024-02-23(102d gap)Verified
- bd_1ea0de9dca288ec8California State AGfiled 2024-02-23(102d gap)Verified
- bd_2a188244340d6000Indiana State AGfiled 2024-02-23(102d gap)Verified
- bd_7db02c0700987958Maine State AGfiled 2024-02-23(102d gap)Candidate
Show 2 more filings ↓Show fewer ↑up to 102d gap
- bd_c00cbc9e0bd76d10Montana State AGfiled 2024-02-23(102d gap)Verified
- bd_cebd1151800de2a6Vermont State AGfiled 2024-02-23(102d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-586359
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 4, 2024
- Raw hash
- 217f758f31cf16ab00b767a2fef17557b3803444a3b64bf2f90e2cf6e0974b40
Reporting entity
- Name
- Crossroads Equipment Lease & Finance, LLCnorm: crossroads equipment lease finance
Victim entity
- Name
- Crossroads Equipment Lease & Finance, LLCnorm: crossroads equipment lease finance
Incident
- Discovered
- Apr 2, 2023
- Materiality determined
- —
- Notification sent
- Jun 3, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSHEALTH_BASICEMPLOYMENTIP
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the Federal Bureau of Investigation
Compliance
- Time to disclose
- 14 months(429 days from discovery to filing)
- Compliance flags
- CA 60-day late · 428d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 2, 2023→ Notified: Jun 3, 2024428d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.