Crimson Wine Group, Ltd.
bd_9737d8201342285b · schema v1 · pii pii-v1
Full breach record for Crimson Wine Group, Ltd. →Crimson Wine Group, Ltd. disclosed that on June 30, 2024, it detected a cybersecurity incident where an unauthorized third party gained access to internal systems and exfiltrated files potentially containing sensitive personal information. On July 25, 2024, the Company determined the incident likely had a material impact on business operations, though not on overall financial condition. The Company contained the incident by isolating systems from the Internet and has since restored operations. It is investigating the extent of personal data exposure, including potential customer data, and plans to notify affected parties and regulators.
J jump to incidentP pin to compareR raw source
Incident timeline
Jun 30, 2024
Discovered
Jul 25, 2024
Filed
vs. sector median
7 wks faster
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Siteabyssbd_26abea618405c74c2024-07-25Verified by operator
Regulatory filings (9) · sorted by filing gap
- SEC 8-Kbd_e827f1c9b467ab992024-07-05 · +20dVerified by operator
- Illinois State AGbd_e0ece01076c1b7162024-12-01 · +129dCandidate
- Washington State AGbd_356c71d91c3449252024-12-13 · +141dVerified
- New Hampshire State AGbd_4daf8961ad661eda2024-12-13 · +141dVerified
Show 5 more filings ↓Show fewer ↑up to 142d gap
- Montana State AGbd_97d469a8862c1d2e2024-12-13 · +141dVerified
- Maine State AGbd_d15098c1f023a7c92024-12-13 · +141dVerified
- Vermont State AGbd_d21fb3856264f6b72024-12-13 · +141dVerified
- Oregon State AGbd_df3b95abdfdf21722024-12-13 · +141dVerified
- Massachusetts State AGbd_e4d202cfe6a12d7a2024-12-14 · +142dVerified
Showing first 10 of 11 linked disclosures.
Filing propagation · 10 filings · 8 states
View merged incident ↗Pattern: first filing Jul 5, last Dec 14 (MA) — a 162-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Cascade drawn from the first 10 linked disclosures of 11 — the full spread may be wider.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.