MalwareRansomwareData EncryptedTargetedIDENTITY_BASICOTHERLowContained
Crossroads Trading Co., Inc.
bd_9903b9cec62fd77f · schema v1 · pii pii-v1
Full breach record for Crossroads Trading Co., Inc. →Crossroads Trading Co., Inc. notified consumers of a February 15, 2025 security incident where an unauthorized third party encrypted data on its network. The incident involved the encryption of data containing names and other categories of personal information. Crossroads engaged forensic investigators and the FBI, secured the network, and is offering two years of Experian identity protection services to affected individuals.
Vermont clock⏱ VT AG >14 bday5 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 4 about the same incident.View merged incident
A leak claim by qilin about this victim predates this filing by 32 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_44202e6cb75889c7Leak Siteqilinfiled 2025-02-21(32d gap)Verified
Regulatory filings (2) · sorted by filing gap
- bd_630daf08ddfcdf2bMaine State AGfiled 2025-03-25Verified
- bd_8680c7a67346983aCalifornia State AGfiled 2025-03-25Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-03-25-crossroads-trading-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 25, 2025
- Raw hash
- b0ca91068857ad14aa90e1fe2d0a2e5fe72d1ed2252b90c14ac2e1ad97a21cb6
Reporting entity
- Name
- Crossroads Trading Co., Inc.norm: crossroads trading
- Domain
- crossroadstrading.com
Victim entity
- Name
- Crossroads Trading Co., Inc.norm: crossroads trading
- Domain
- crossroadstrading.com
Incident
- Discovered
- Feb 15, 2025
- Materiality determined
- —
- Notification sent
- Mar 25, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICOTHER
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported this incident to and met with the FBI
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(38 days from discovery to filing)
- Compliance flags
- VT AG >14 bdayLeak >30d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.