Attorneys at Almeida Law Group are investigating whether a class action lawsuit can be filed on behalf of individuals affected by a possible Crossett data breach. According to dark web monitoring sources, a hacker group calling itself termite claimed responsibility for a cyberattack on Crossett in a post first observed in September 2026, alleging it had gained access to internal company systems. As of this writing, Crossett has not issued a public confirmation of the incident, and the exact scope of any exposed data remains unknown. If you believe you were affected, contact Almeida Law Group.
About Crossett
Crossett, Inc. is a privately owned petroleum transport company founded in 1928 and headquartered in Warren, Pennsylvania. The company transports petroleum-based products — including gas, diesel, asphalt, oil, solvents, glues, and waxes — across major markets in the Eastern U.S. and Ontario, Canada, operating a fleet of more than 100 Peterbilt tractors and 210 trailers. Crossett also provides cargo tank repair, testing, inspection, and truck tractor maintenance services. As of mid-2025, the company employed approximately 76 people and reported an estimated $15 million in annual revenue.
What Happened?
On September 26th, 2026, Ransomware.live reported that the Termite ransomware group listed Crossett on its dark-web leak site. The estimated attack date cited by Ransomware.live is September 25th, 2026. This is an attacker-side allegation only. No public confirmation from Crossett or any regulatory body has been found, and no independent corroborating news coverage of this specific incident was located. The types of data involved, the volume of any allegedly exfiltrated files, and the number of individuals potentially affected have not been disclosed by any source.
Termite is a ransomware group first identified in late 2024 that uses a modified version of Babuk ransomware code and conducts double-extortion operations, combining data theft with ransomware deployment. The group’s most notable prior attack was the November 2024 breach of supply-chain software firm Blue Yonder, in which it claimed 680 GB of exfiltrated data. Termite has claimed victims across healthcare, manufacturing, technology, professional services, and education sectors, predominantly in the United States.
Key Facts at a Glance
- Company or Organization: Crossett, Inc.
- Industry: Truck Transportation / Petroleum Transport (SIC 4213; NAICS 484)
- Location: Warren, Pennsylvania, US
- Incident type: Ransomware claim (dark-web leak-site allegation; attacker-side only)
- Date of breach: September 25th, 2026 (estimated attack date per Ransomware.live; not confirmed by Crossett)
- Source: Ransomware.live – Victim: Crossett (Termite), Ransomware.live – Termite group profile, Mallory.ai – Termite threat actor profile, Crossett, Inc. official website, Crossett, Inc. on Craft.co
What Should You Do?
If you are a Crossett employee, customer, or business contact and believe your information may have been involved, you should take precautionary steps now. Consider placing a fraud alert or credit freeze with the three major credit bureaus — Equifax, Experian, and TransUnion — to help prevent unauthorized accounts from being opened in your name. Monitor your financial accounts and credit reports closely for any suspicious activity, and request your free annual credit reports at AnnualCreditReport.com. If you become a victim of identity theft or fraud, report it and get a recovery plan at IdentityTheft.gov.
Your Legal Rights
If your personal information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.