DisclosureLens
Social EngineeringHealthcareHealthcareBECStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIdentity (basic)Government IDHealth (basic)PHIMediumContained

Crossroads for Women

bd_a20f1b4581e0b351 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Aug 25, 2023

Filed

Jan 17, 2024

To disclose

21 weeks

Affected

Not disclosed

Linked

2 filings

Confidence

67%
Full breach record for Crossroads for Women2 incidents on file

Crossroads for Women experienced a business email compromise (BEC) detected on August 25, 2023. An unauthorized party accessed an email account, potentially exposing sensitive personal information including names, dates of birth, medical/health information, insurance details, and Social Security numbers for some individuals. The organization secured the account, changed credentials, and enhanced security measures. Affected individuals are offered credit monitoring and fraud assistance services.

Vermont clock VT AG >45 bday21 weeks discovery → filing

Incident timeline

discovery → filing · 21 weeks / 145 days

Aug 25, 2023

Discovered

Jan 17, 2024

Filed

vs. sector median

+8 wks slower

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
Vermont State AGJan 17 · first · this page

Pattern: first filing Jan 17 (VT), last Jan 22 (NH) — a 5-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.