October data incident may have jeopardized customer information, says C.R. England.

C.R. England, a truckload carrier, alerted clients this week that their personal information may have been stolen in a data breach that happened last October.

A C.R. England spokeswoman acknowledged the letter, which stated that the corporation had been the victim of “unauthorized activity” in its systems on October 30, 2021.

“In response, we quickly commenced containment, mitigation, and restoration steps to stop the activity and safeguard our network, systems, and data,” the letter stated. “In addition, we recruited independent cybersecurity specialists to perform a forensic investigation into the issue and aid us in identifying what transpired.”

The procedure took time, and according to the C.R. England letter, it wasn’t until April 20 that the company decided the files compromised by the data breach “included some of your personal information.”

In a post on the legal website J.D. Supra, Richard Console of the law firm Console & Associates stated that the breach is thought to have affected approximately 224,500 people whose Social Security information may have been exposed.

TJ England, the company’s chief legal officer, said in a statement sent to FreightWaves that it was the first such breach that C.R. England had suffered.

“C.R. England has alerted possibly affected persons and established a call center to resolve any inquiries from those individuals,” he said. “C.R. England has no reason to suspect that any material involved was or will be published, disseminated, or otherwise exploited.”

Following the hack and prior to the April 20 conclusion on the impact of the cyberattack, the company “examined the compromised files to determine the individuals whose personal information may have been touched by this incident and the types of information implicated for each individual.”

C.R. England said it was providing affected customers with one or two years of free identity theft protection from IDX, which it characterized as a “data breach and identity recovery services expert.” It also notified the FBI about the intrusion.

The Console law firm stated on its website that it will seek to interview “victims of the breach to ascertain what damages they experienced and what legal claims may be available to them.”