2025 Crossroads Trading — network intrusion; 60,041 people (SSNs, DL/gov IDs); Qilin claim
Data compromised
Names, dates of birth, addresses, contact information, Social Security numbers, driver’s license or state ID numbers, financial account information, passport information (per settlement notice)
Technical writeup
Verified company and regulator notices — February 15, 2025 intrusion at Crossroads Trading Co., Inc. (nationwide secondhand apparel reseller). Forensics found an unauthorized party accessed and encrypted data on a limited network segment; IT contained the incident and restored systems. Texas AG filing (March 26, 2025) and New Hampshire notice (March 25, 2025) cite approximately 60,041 individuals — customers, sellers, and current/former employees — with names, Social Security numbers, driver’s license or other government ID numbers, and additional fields in the class-action settlement (DOB, addresses, contact info, financial account and passport data). Qilin posted a dark-web claim February 21, 2025 with sample screenshots; Crossroads mailed breach letters beginning March 25, 2025 and offered Experian IdentityWorks credit monitoring. A $600,000 class settlement (Koester v. Crossroads) was approved with claims through October 13, 2026. recordsAffected 60041 from AG/settlement filings; companyConfirmed true.
Root cause
Unauthorized party accessed and encrypted a segment of Crossroads Trading network (Feb 15, 2025); Qilin ransomware group claimed responsibility Feb 21, 2025