LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Crossroads Trading Co., Inc. Data Breach Notice (Oregon Attorney General)

MEDIUM severityConfirmedHow we verify

Crossroads Trading Co., Inc. Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·March 25, 2025
Crossroads Trading Co., Inc. Data Breach Notice (Oregon Attorney General)

Occurred February 15, 2025 · publicly disclosed March 25, 2025. Approximately 60041 people affected.

MEDIUM
Severity
60041
People affected
1
Data types exposed
March 25, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Crossroads Trading Co., Inc. disclosed a data breach on March 25, 2025, involving the personal information of 60,041 individuals; the breach occurred on February 15, 2025. Affected residents are advised to review the notice filed with the Oregon Attorney General and take any recommended protective steps.

Severity & verification
MEDIUM severityConfirmed
Data types not itemised.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
60041 accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Data breaches remain a steady feature of the current threat landscape: retailers and consumer-facing companies continue to face attempts to reach customer and employee records, often with limited public detail about how access occurred. Against that backdrop, Crossroads Trading Co., Inc. has disclosed a security incident that the company reported to Oregon authorities, putting tens of thousands of people within the scope of official notice.

According to a filing with the Oregon Department of Justice reported on March 25, 2025, Crossroads Trading Co., Inc. notified Oregon residents of a data breach. The same filing places the incident itself on February 15, 2025, and states that 60,041 people were affected. The notice describes the exposed material as personal information. Public detail beyond those points is limited.

Breaking down the breach

What is known comes from the company’s breach notification as reflected in the Oregon Attorney General / Department of Justice reporting channel. Crossroads Trading Co., Inc. identified an incident dated February 15, 2025. The organization later submitted notice that was reported on March 25, 2025. The filing states that 60,041 individuals were affected and that personal information was involved, per the breach notification.

The public record available from that disclosure does not describe the technical method of intrusion, whether ransomware or other malware was used, how long unauthorized access lasted, which systems were involved, or whether data was exfiltrated, viewed only, or otherwise misused. No threat actor is named in the facts provided. Those elements remain undisclosed in the material summarized here.

How a breach like this happens

In general terms—and not as a description of this specific case—incidents that lead to notices about “personal information” often begin with common entry paths. Attackers may obtain valid credentials through phishing, password reuse, or stolen session data; exploit unpatched remote services; or abuse a compromised vendor or cloud connection that already has access to customer or employee databases. Once inside, they may search for files, exports, or applications that hold names, contact details, account identifiers, or other records useful for fraud or resale.

Detection can lag days or weeks if logging is incomplete or if the activity blends with normal traffic. Organizations then investigate, determine what categories of data were in the affected environment, and issue notices when law or policy requires it. None of that sequence is confirmed for Crossroads Trading Co., Inc. beyond the dates, headcount, and “personal information” label in the Oregon filing; the paragraphs above are background on how breaches of this broad type typically unfold.

Who is Crossroads Trading Co., Inc.?

Crossroads Trading Co., Inc. is a consumer retail business known for buying and selling used and consigned clothing and accessories through physical stores and related customer channels. Companies in this sector routinely maintain records needed to run loyalty or buy-sell programs, process payments or store credit, manage employee payroll and HR files, and communicate with shoppers—information that can include names, addresses, phone numbers, email addresses, and other account-related details.

A breach notice from such an organization matters because the customer base is broad and transactional. Even when only a subset of records is confirmed exposed, the scale of retail operations means notices can reach tens of thousands of people, as reflected in the 60,041 figure reported here. The consequential issue is not brand reputation alone but the practical risk that personal data, once outside the organization’s control, can be misused in identity or account fraud.

The information in question

The breach notification, as reported, names the exposed data as personal information. It does not, in the facts provided, list a field-by-field inventory such as Social Security numbers, payment-card full data, driver’s license numbers, or medical information. Exact contents beyond the “personal information” designation are therefore unconfirmed in the public summary used for this article.

Organizations of this kind typically hold customer contact and transaction-related data, and may also hold employee information. Readers should treat only the categories stated in official notices as established for this incident and should not assume additional sensitive fields were involved unless a later disclosure says so.

The real-world impact

For affected individuals, the primary risks tied to personal information exposure are secondary misuse: targeted phishing that references a real relationship with the retailer, account takeover attempts on email or shopping accounts if credentials or recovery data were involved, and longer-term identity fraud if richer identifiers were present—something not confirmed here. Oregon residents were among those notified; the total affected count of 60,041 indicates the incident was not limited to a handful of accounts.

For the organization, consequences include the cost of investigation and notification, possible regulatory follow-up under state breach laws, customer support load, and the need to harden systems after the February 15, 2025 incident. Public reporting does not establish negligence as fact; it establishes that a reportable event occurred and was disclosed through the Oregon channel on the March 25, 2025 reporting date.

If your data was in this breach

If you received a notice from Crossroads Trading Co., Inc., or if you were a customer or employee in the relevant period, treat the company’s letter as the authoritative source for what applied to you. Practical first steps are straightforward and do not require panic:

You can also run a free exposure scan of your email address to check whether that address has already appeared in other known breach datasets, which helps separate this incident from older, unrelated exposures. Stay alert to official updates from the company or regulators rather than unverified social media claims, and remember that public detail on method and full data inventory for this event remains limited to what the Oregon filing and the company’s notification have stated.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

CompanyCrossroads Trading Co., Inc. security record
74/100
DoxxScan™ · Moderate doxx risk
B 80Good record

1 reported incident on record.

See Crossroads Trading Co., Inc.’s full breach history →

More recent breaches

Decisely Insurance Services Data Breach Notice (Oregon Attorney General)December 30, 2025Apro, LLC d/ Data Breach Notice (Oregon Attorney General)December 29, 2025Apro, LLC d/b/a United Pacific Data Breach Notice (Oregon Attorney General)December 29, 2025CareOregon Data Breach Notice (Oregon Attorney General)December 26, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Crossroads Trading Co., Inc. Data Breach Notice (Oregon Attorney General) →

Source: Oregon Department of Justice breach notification

Verified breach

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram