DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Almost two years later, Alpha Omega Winery notifies those affected by a data breach. (1)

Posted on November 12, 2025November 28, 2025 by Dissent

Some wines benefit from aging. Breach notification letters do not.

On or about December 28, 2023, Alpha Omega Winery in California experienced what they report as a ransomware incident.

According to their notification, the types of personal information may have included, and potentially were not limited to: name, date of birth, Social Security number, driver’s license/state ID number, passport number, other government identification number, health insurance policy number, and medical information.

The winery appeared to be first notifying those affected on or about November 6, 2025 — or that is when they submitted a copy of the notification letter to the California Attorney General’s Office. If they mailed the letter more promptly, there is no indication of that in their submission. There is no indication that the notification was delayed due to any law enforcement involvement.

The letter contains an offer of two years of complimentary credit report monitoring and restoration services provided by Cyberscout. The letter was not signed by any executive or principal of the firm.

DataBreaches emailed the winery on November 7 to ask whether any files or servers were actually encrypted or if this was a case of data exfiltration with a ransom demand. DataBreaches also asked why it took the winery almost two years to notify those affected.

The inquiry was read by two individuals on November 7, including their Chief Operations Officer, but no one replied to the inquiry, and they still haven’t.

This incident was never claimed by any of the ransomware gangs indexed by a popular indexing site, so what happened and how the winery responded is still unknown. Nor do we know how many customers and/or employees may have been affected.

Update of November 27, 2025: They still have not replied. The winery has a privacy policy page on its website. Given the sensitivity of the data that was involved, it is a shame that they are not more transparent or timely in disclosing this breach.

Not read: Media Inquiry About Data Breach

From Robin Baggett on 2025-11-27 16:43

Your message

To: Robin Baggett
Subject: Media Inquiry About Data Breach
Sent: Friday, November 7, 2025 11:05:12 AM (UTC-08:00) Pacific Time (US & Canada)

was deleted without being read on Thursday, November 27, 2025 1:43:25 PM (UTC-08:00) Pacific Time (US & Canada).

Final-recipient: RFC822; [email protected]

Category: Business SectorHackU.S.

Post navigation

← Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs
Amendment 13 is gamechanger on data security enforcement in Israel →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Defense Bill Would Require New Cyber Requirements for Some DoD Telecom Contracts
  • Tell the truth, or someone will tell it for you — Trumbull County, Ohio edition (1)
  • US Posts $10 Million Bounty for Iranian Hackers
  • South Korea police raid e-commerce giant Coupang over data leak; govt schedules hearing
  • FinCEN Report: Reported Ransomware Incidents and Payments Reached All-Time High in 2023
  • Leavenworth, Kansas cyberattack disrupts city services
  • They’ve escaped a lot of media attention, but Anubis RaaS is a threat to the medical sector (1)
  • “In the most expedient time possible…”
  • Portugal updates cybercrime law to exempt security researchers
  • LockBit 5’s “new secure blog domain” infra leaked already

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • FTC Denies Petition from SpyFone App CEO to Vacate 2021 Order
  • Privacy concerns raised as Grok AI found to be a stalker’s best friend
  • PRIVACY—S.D. Cal.: Employee did not waive privacy right in personal email data on company provided laptop, (Dec 5, 2025)
  • EU justice chief draws red line on privacy reforms
  • Kaiser Permanente to Pay Up to $47.5M in Web Tracker Lawsuit

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: Dissent.73
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.