Skip to content

Crimson Wine Group

Disclosed Jul 5, 20242 years agoConfirmed

Official notice

Material cybersecurity incident reported to the SEC (8-K Item 1.05)

(the "Company") determined that the Company had experienced a cybersecurity incident in which an unauthorized third party gained access to certain technology systems of the Company. The Company currently believes that this unauthorized third party gained such access on June 30, 2024. Following detection of the incident, the Company initiated response protocols and launched an investigation, which remains ongoing. The Company is in the early stages of its investigation and assessment of this incident. The full scope of the costs and related impacts of this incident has not been determined. The

What is known

People affectedNot stated in the sources we have
DisclosedJul 5, 2024
DiscoveredJun 30, 2024
HappenedJun 26, 2024
AttackRansomware
Data exposedNot stated
SectorRetail · US
StatusConfirmed

Sources

Source
Washington Attorney General breach notice: Crimson Wine Groupatg.wa.gov · Official notice
Oregon DOJ breach notice: Crimson Wine Groupjustice.oregon.gov · Official notice
Crimson Wine Group, Ltd Form 8-K, Item 1.05 (2024-07-25)sec.gov · SEC filing
Vermont Attorney General: 2024-12-13 Crimson Wine Group Data Breach Notice to Consumersago.vermont.gov · Official notice
Crimson Wine Group, Ltd Form 8-K, Item 8.01 (2024-07-05)sec.gov · SEC filing

Notices filed

WhereFiledPeople
SEC 8-K 8.01totalJul 5, 2024
SEC 8-KtotalJul 25, 2024
Washington AGresidents of WADec 13, 20243,436
Oregon DOJresidents of ORDec 13, 202426,238
Vermont AGresidents of VTDec 13, 2024
History of this record
  • 2026-09-25 · disclosed: 2024-07-25 to 2024-07-05 · backfill source
  • 2026-09-25 · summary: empty to (the "Company") determined that the Company had experienced a cybersecurity incident in which an unauthorized third party gained access to certain technology systems of the Company. The Company currently believes that this unauthorized thir · backfill source
  • 2026-09-25 · source: empty to https://ago.vermont.gov/document/2024-12-13-crimson-wine-group-data-breach-notice-consumers · backfill source
  • 2026-09-25 · disclosed: 2024-12-13 to 2024-07-25 · backfill source
  • 2026-09-25 · title: empty to Material cybersecurity incident reported to the SEC (8-K Item 1.05) · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Washington AG), confirmed by Washington AG. Record counts are as reported. Not legal advice.

Everything about Crimson Wine Group

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.