MalwareRansomwareData EncryptedRansom DemandedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSHEALTH_BASICMediumContained
Crossroads Equipment Lease & Finance, LLC
bd_cebd1151800de2a6 · schema v1 · pii pii-v1
Full breach record for Crossroads Equipment Lease & Finance, LLC →Crossroads Equipment Lease & Finance, LLC notified customers of a ransomware attack on April 1, 2023, which encrypted systems and potentially exposed personal information including SSNs, DOBs, driver's licenses, and financial data. The company engaged the FBI, secured systems, and offered 24 months of credit monitoring.
Vermont clock✗ VT AG >45 bday47 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_0ad92da3eea5bc49New Hampshire State AGfiled 2024-02-23Verified
- bd_1ea0de9dca288ec8California State AGfiled 2024-02-23Verified
- bd_2a188244340d6000Indiana State AGfiled 2024-02-23Verified
- bd_7db02c0700987958Maine State AGfiled 2024-02-23Candidate
Show 2 more filings ↓Show fewer ↑up to 102d gap
- bd_c00cbc9e0bd76d10Montana State AGfiled 2024-02-23Verified
- bd_2ecc67df1c6bd825California State AGfiled 2024-06-04(102d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-02-23-crossroads-equipment-lease-finance-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 23, 2024
- Raw hash
- 3bf4d9d4d65f5aaedfc524942c722bd1915f31441fc154b71678e36e69caa660
Reporting entity
- Name
- Crossroads Equipment Lease & Finance, LLCnorm: crossroads equipment lease finance
Victim entity
- Name
- Crossroads Equipment Lease & Finance, LLCnorm: crossroads equipment lease finance
Incident
- Discovered
- Apr 2, 2023
- Materiality determined
- Feb 23, 2024
- Notification sent
- Feb 23, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSHEALTH_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the Federal Bureau of Investigation
Compliance
- Time to disclose
- 47 weeks(327 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.