Crimson Wine Group, Ltd.
ent_019e20cebd3e4d85711c5216a66593c1
Disclosures
12
State AG · Leak Site · SEC 8-K · 10 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
26,238
nationwide · State AG ME
Leak-site claims
2
unverified actor claims
Identity resolution
- Canonical name
- Crimson Wine Group, Ltd.
- Normalized
- crimson wine— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 254900L67L3ONFDU2R82
- SEC EDGAR CIK
- 0001562151
- Domain
- crimsonwinegroup.com
Disclosure history (12)newest first
- Massachusetts State AGas victim2024-12-14
Crimson Wine Group reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-12-14. 212 Massachusetts residents were affected.
- Washington State AGas victim2024-12-13
Crimson Wine Group reported a ransomware cyberattack in Washington state. Unauthorized access occurred June 26-30, 2024, discovered June 30, 2024. Affected data included names, SSNs, driver's licenses, financial accounts, and medical info. 3,421 Washington residents notified. Response included law enforcement notification and credit monitoring.
- New Hampshire State AGas victim2024-12-13
Crimson Wine Group notified New Hampshire residents on December 13, 2024, of a cybersecurity incident discovered on June 30, 2024. An unauthorized third party gained access to systems between June 26 and June 30, 2024, potentially viewing or taking personal information. 59 NH residents were notified. Crimson notified federal law enforcement, provided credit monitoring via IDX, and implemented additional safeguards.
- Montana State AGas victim2024-12-13
Crimson Wine Group notified Montana residents of a cybersecurity incident discovered on June 30, 2024. Unauthorized access occurred between June 26-30, 2024, potentially exposing names and other personal information. The company secured its network, notified federal law enforcement, and is offering credit monitoring services.
- Maine State AGas victim2024-12-13
Crimson Wine Group experienced an external system breach (hacking) between June 26 and June 30, 2024. The incident compromised the personal information (name, financial account, and payment card data) of approximately 26,238 individuals, including 21 Maine residents. The company notified federal law enforcement and provided one year of credit monitoring services through IDX to affected individuals.
- Vermont State AGas victim2024-12-13
Crimson Wine Group notified consumers of a cybersecurity incident where an unauthorized third party accessed systems between June 26-30, 2024. The incident involved personal information (names). The company secured the network, notified federal law enforcement, and offered credit monitoring services. No evidence of identity theft was found.
- Oregon State AGas victim2024-12-13
Crimson Wine Group reported a data breach to the Oregon Attorney General. The breach was reported on 2024-12-13. 26,238 individuals were affected.
- Illinois State AGas victim2024-12-01
CRIMSON WINE GROUP filed a data-breach notice with the Illinois Attorney General in December 2024 (case 24-12-022). The register records the breach as discovered on June 26, 2024. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- GLOBALLeak Siteas victim2024-07-25
crimsonwinegroup.com.com 1.6Tb uncompressed data
- FEDERALSEC 8-Kas victim2024-07-25
Crimson Wine Group, Ltd. disclosed that on June 30, 2024, it detected a cybersecurity incident where an unauthorized third party gained access to internal systems and exfiltrated files potentially containing sensitive personal information. On July 25, 2024, the Company determined the incident likely had a material impact on business operations, though not on overall financial condition. The Company contained the incident by isolating systems from the Internet and has since restored operations. It is investigating the extent of personal data exposure, including potential customer data, and plans to notify affected parties and regulators.
- FEDERALSEC 8-Kas victim2024-07-05
Crimson Wine Group, Ltd. filed an 8-K on July 5, 2024, reporting a cybersecurity incident discovered on June 30, 2024. An unauthorized third party gained access to certain technology systems. The Company is in the early stages of its investigation, and the scope of costs and impacts has not been determined. The incident status is active.
- GLOBALLeak Siteas victim2024-06-30
crimsonwinegroup.com.com 1.6Tb uncompressed data