Crimson Wine Group, Ltd.
ent_019e20cebd3e4d85711c5216a66593c1
Disclosures
10
State AG · Leak Site · SEC 8-K · 8 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
26,238
as filed · State AG OR
Leak-site claims
2
unverified actor claims
Identity resolution
- Canonical name
- Crimson Wine Group, Ltd.
- Normalized
- crimson wine— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 254900L67L3ONFDU2R82
- SEC EDGAR CIK
- 0001562151
- Domain
- crimsonwinegroup.com
Disclosure history (10)newest first
- 🌲Washington State AGas victim2024-12-13
Crimson Wine Group, a business sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2024-06-30 and filed notice on 2024-12-13. 3,436 Washington residents were affected. 166 days elapsed between awareness and notification. 4 days to identify the breach. 0 days to contain the breach.
- ⛰️New Hampshire State AGas victim2024-12-13
Crimson Wine Group notified New Hampshire residents on December 13, 2024, of a cybersecurity incident discovered on June 30, 2024. An unauthorized third party gained access to systems between June 26 and June 30, 2024, potentially viewing or taking personal information. 59 NH residents were notified. Crimson notified federal law enforcement, provided credit monitoring via IDX, and implemented additional safeguards.
- 🦬Montana State AGas victim2024-12-13
Crimson Wine Group reported a data breach to the Montana Attorney General. The breach was reported on 2024-12-13. The breach occurred from 06/26/2024 to 06/30/2024. 17 Montana residents were affected.
- 🦞Maine State AGas victim2024-12-13
Crimson Wine Group experienced an external system breach (hacking) between June 26, 2024, and June 30, 2024. The breach was discovered on July 15, 2024. The incident affected 26,238 individuals in total, including 21 residents of Maine. Affected individuals were notified on August 19, 2024, and offered 12 months of identity monitoring services from IDX.
- 🍁Vermont State AGas victim2024-12-13
Crimson Wine Group notified consumers of a cybersecurity incident where an unauthorized third party accessed systems between June 26-30, 2024. The incident involved personal information (names). The company secured the network, notified federal law enforcement, and offered credit monitoring services. No evidence of identity theft was found.
- 🦫Oregon State AGas victim2024-12-13
Crimson Wine Group reported a data breach to the Oregon Attorney General. The breach was reported on 2024-12-13. 26,238 individuals were affected.
- GLOBALLeak Siteas victim2024-07-25
crimsonwinegroup.com.com 1.6Tb uncompressed data
- FEDERALSEC 8-Kas victim2024-07-25
Crimson Wine Group disclosed on July 25, 2024 that a June 30, 2024 cybersecurity incident involving unauthorized third-party access to internal systems and exfiltration of files (potentially including sensitive personal information) has likely had a material impact on business operations. The company shut down systems to contain the incident, engaged external cybersecurity experts, and has substantially restored affected systems. Scope of personal information exposure is still under investigation.
- FEDERALSEC 8-Kas victim2024-07-05
Crimson Wine Group, Ltd. filed an 8-K on July 5, 2024, reporting a cybersecurity incident discovered on June 30, 2024. An unauthorized third party gained access to certain technology systems. The Company is in the early stages of its investigation, and the scope of costs and impacts has not been determined. The incident status is active.
- GLOBALLeak Siteas victim2024-06-30
crimsonwinegroup.com.com 1.6Tb uncompressed data