A.T. Cross Company
bd_dcc72d5a1b23f814 · schema v1 · pii pii-v1
Full breach record for A.T. Cross Company →A.T. Cross Company notified the NH AG of a data event affecting 5 NH residents. Payment card data (name, address, card number, expiration, CVV) was potentially acquired without authorization from purchases made on www.cross.com between May 9-14, 2019. The incident was discovered in May 2019 when the checkout page behaved abnormally. Forensic investigation confirmed the breach. Notices were sent on June 26, 2019.
J jump to incidentP pin to compareR raw source
Incident timeline
May 9, 2019
Begins
Jul 1, 2019
Filed
vs. sector median
+1 wks slower
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Massachusetts State AGbd_16c1ace52e487dbb2019-06-26 · +5dVerified
- Montana State AGbd_660e8e209d23556e2019-06-26 · +5dCandidate
- New Hampshire State AGbd_f5d50bceeeda54b82019-06-26 · +5dVerified
Filing propagation · 4 filings · 3 states
View merged incident ↗Pattern: first filing Jun 26 (MA), last Jul 1 (NH) — a 5-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.