Crimson Wine Group
Disclosed Jul 5, 20242 years agoConfirmed
Material cybersecurity incident reported to the SEC (8-K Item 1.05)
(the "Company") determined that the Company had experienced a cybersecurity incident in which an unauthorized third party gained access to certain technology systems of the Company. The Company currently believes that this unauthorized third party gained such access on June 30, 2024. Following detection of the incident, the Company initiated response protocols and launched an investigation, which remains ongoing. The Company is in the early stages of its investigation and assessment of this incident. The full scope of the costs and related impacts of this incident has not been determined. The
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Jul 5, 2024 |
| Discovered | Jun 30, 2024 |
| Happened | Jun 26, 2024 |
| Attack | Ransomware |
| Data exposed | Not stated |
| Sector | Retail · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Washington Attorney General breach notice: Crimson Wine Groupatg.wa.gov · Official notice | Official notice |
| Oregon DOJ breach notice: Crimson Wine Groupjustice.oregon.gov · Official notice | Official notice |
| Crimson Wine Group, Ltd Form 8-K, Item 1.05 (2024-07-25)sec.gov · SEC filing | SEC filing |
| Vermont Attorney General: 2024-12-13 Crimson Wine Group Data Breach Notice to Consumersago.vermont.gov · Official notice | Official notice |
| Crimson Wine Group, Ltd Form 8-K, Item 8.01 (2024-07-05)sec.gov · SEC filing | SEC filing |
Notices filed
| Where | Filed | People |
|---|---|---|
| SEC 8-K 8.01total | Jul 5, 2024 | |
| SEC 8-Ktotal | Jul 25, 2024 | |
| Washington AGresidents of WA | Dec 13, 2024 | 3,436 |
| Oregon DOJresidents of OR | Dec 13, 2024 | 26,238 |
| Vermont AGresidents of VT | Dec 13, 2024 |
History of this record
- 2026-09-25 · disclosed: 2024-07-25 to 2024-07-05 · backfill source
- 2026-09-25 · summary: empty to (the "Company") determined that the Company had experienced a cybersecurity incident in which an unauthorized third party gained access to certain technology systems of the Company. The Company currently believes that this unauthorized thir · backfill source
- 2026-09-25 · source: empty to https://ago.vermont.gov/document/2024-12-13-crimson-wine-group-data-breach-notice-consumers · backfill source
- 2026-09-25 · disclosed: 2024-12-13 to 2024-07-25 · backfill source
- 2026-09-25 · title: empty to Material cybersecurity incident reported to the SEC (8-K Item 1.05) · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Washington AG), confirmed by Washington AG. Record counts are as reported. Not legal advice.