Claims are open, and the window is short. The deadline to file is September 1, 2026. The settlement resolves
Kaplan v. Crimson Wine Group, Ltd., Case No. 25CV001571, in the Superior Court of California for
the County of Napa, and it has not received final approval yet. No payment date has been announced. If a
notice reached you, have it in hand before you sit down to file — with less than a week left, an unresolved
missing-notice problem is the thing most likely to cost someone their claim.
Status
Claims Open
closing soon · not yet granted final approval
Claim Deadline
September 1, 2026
online or by mail
Estimated Payout
About $100, or up to $5,000
$637,500 fund · the $100 is an estimate, not a fixed figure · two years of credit monitoring alongside either route
Proof Required
Yes
documentation for the $5,000 tier · have the notice you were sent when you file online
The settlement is open and closing shortly. Crimson Wine Group, Ltd. has agreed to a $637,500 settlement to
resolve the class action, and the claim portal, the notice and the settlement documents are live on the
official settlement website. The complaint was filed on July 30, 2025 in Napa County Superior Court; the
parties agreed to settle rather than carry the costs, risks and uncertainties of continuing the litigation.
Crimson Wine Group denies the allegations, and no court has found that it did anything wrong.
Crimson Wine Group, Ltd. is a wine producer headquartered in Napa, California, with estates across several
West Coast growing regions. According to the settlement, a targeted cyberattack on the company's computer
systems in or about June 2024 gave an attacker access to files that may have contained personal
information, including names, Social Security numbers and financial account information.
The underlying complaint described a broader set of data and a specific window. It alleged that a cyberattack
between June 26 and June 30, 2024 compromised the personal data of at least 26,000 people, including names,
addresses, Social Security numbers, driver's license numbers, financial information, medical information and
dates of birth. Those figures come from the complaint and are allegations rather than findings.
What makes this combination worth taking seriously is not the size of the class — 26,000 is small as these
things go — but the composition of the data. A name paired with a Social Security number and a date of birth
is the raw material for opening credit in someone else's name, and none of the three can be reissued the way
a compromised card number can.
The Settlement Class covers people nationwide whose private information was involved in the June 2024
incident. Membership turns on whether your information was caught up in the attack and you were identified
as affected, not on whether you ever bought anything from the company — which is why the notice sent by the
settlement administrator is the practical marker of who is in.
If you believe you were affected but no notice reached you, do not assume you are covered and do not wait.
Use the contact route on the official settlement website to reach the administrator, and do it now rather
than in the final days before September 1.
The $637,500 fund pays out along two cash routes plus a monitoring benefit:
- A flat cash payment estimated at $100, with no documentation required.
- Reimbursement of up to $5,000 for documented losses tied to the breach, in place of the flat payment.
- Two years of credit monitoring.
The $100 is an estimate, and the distinction matters more here than on a settlement with a larger fund.
$637,500 spread across roughly 26,000 notified people is about $24.50 a head before anything is deducted —
so the $100 figure assumes that a substantial share of the class never files, which is what usually happens.
If claim rates run higher than the administrator projected, the per-person figure comes down. It is a
planning number, not a promise.
That arithmetic is also the argument for the documented route if you have anything real to document. The
$5,000 ceiling is fixed and does not shrink because other people filed. Anyone who paid for credit
monitoring out of pocket after the notice, absorbed a fraudulent charge, or spent money replacing
identification should price that path before defaulting to the flat payment.
The documented tier requires documentation, and it has to connect the loss to this incident — receipts, bank
or card statements showing the charge or fee, invoices for a monitoring service you paid for yourself,
records of what replacing an ID cost you. Anything a bank, insurer or employer already reimbursed cannot be
claimed a second time.
The flat cash payment requires no documentation of loss. Filing online, however, is a different question
from documenting a loss: portals for settlements of this size are typically gated on the identifier printed
on the notice the administrator mailed or emailed you. That identifier is itself a form of proof, because
someone who never received the notice cannot produce it. Find your notice before you start, and if you
cannot, contact the administrator through the official settlement website immediately given how little time
is left.
September 1, 2026. The published materials give the date without specifying a cut-off time or a timezone, so
treat the date itself as the deadline. With the window this short, filing online rather than by mail removes
the postmark question entirely.
The deadlines to exclude yourself from the class or to object are set out in the notice and are separate
decisions from filing. Excluding yourself means giving up any payment here to keep the right to sue over
this incident on your own. Doing nothing means you stay in the class, receive nothing, and are still bound
by the release if the settlement is approved.
File on the official settlement website,
Crimson Wine Settlement,
which is the only court-authorized site for this case. Decide between the flat payment and the documented
tier before you begin, and enroll in the credit monitoring in the same sitting.
If you are claiming documented losses, attach the records with the form. A documented claim filed without
documentation is the most common way this kind of claim ends up paying nothing.
The claim window closes September 1, 2026. After that the Court will consider whether to grant final
approval at a fairness hearing; the date is set out in the notice on the official settlement website.
A hearing being held is not the same as approval being granted, and approval is not the same as payments
going out. No payment date has been announced. Money in settlements of this shape moves only after final
approval and after any appeals are resolved. We will update this page when the Court rules and again if a
distribution date is published.
Is the $100 cash payment guaranteed?
No. It is described as an estimate, and that word is doing real work. The settlement fund is $637,500,
and roughly 26,000 people were notified. After documented-loss claims, two years of credit
monitoring for everyone who wants it, notice and administration costs, attorneys' fees and any
service award are taken out, what remains is divided among the people who chose the flat cash
option. If more people claim it than the administrator projected, the figure comes down. If fewer
claim, it can go up. Treat $100 as a planning number rather than a promise.
Can I take the estimated $100 and also claim documented losses?
Data breach settlements built this way almost always make the flat cash payment an alternative to the
documented tier rather than an addition to it, which is why it is usually called an alternative cash
payment. The Claim Form is the document that settles the question for this case, and it states the
election in binding terms. Read it before you submit, because the choice cannot be revisited after
the deadline. Credit monitoring normally sits outside that choice and can be taken alongside
whichever cash route you pick.
What information was involved in the Crimson Wine breach?
The settlement describes a targeted cyberattack on Crimson Wine Group's computer systems in or about
June 2024, in which accessed files may have contained personal information including names, Social
Security numbers and financial account information. The underlying complaint alleged a broader set,
including addresses, dates of birth, driver's license numbers and medical information, for at least
26,000 people. A name paired with a Social Security number and a date of birth is the core material
for identity theft, and unlike a card number none of those three can be reissued.
Why is a California state court handling this instead of a federal court?
The case was filed in the Superior Court of California for the County of Napa, where Crimson Wine
Group is based, as Kaplan v. Crimson Wine Group, Ltd., Case No. 25CV001571. Data breach
class actions can proceed in either system depending on how the claims are pleaded and whether the
parties seek to move the case. For a class member the practical difference is small: the settlement
is still supervised and has to be approved by a judge, the class release still binds you if you do
nothing, and the deadline still governs.
I bought wine from one of the company's brands. Does that make me a class member?
Not by itself. Membership turns on whether your personal information was involved in the incident and
you were identified as affected, not on whether you were a customer. The notice sent by the
settlement administrator is the practical marker. If you believe you were affected but never
received one, use the contact route on the official settlement website to reach the administrator
well before the deadline rather than assuming you are covered.
For more class actions keep scrolling below.
Settlement Amount
$637,500
Case Title
Kaplan v. Crimson Wine Group, Ltd.
Case Number
25CV001571
Court
Superior Court of California, County of Napa
Free settlement alerts
Get notified when new class actions open to claims
Join thousands of readers who get the latest class action settlements you may qualify for — delivered straight to your inbox.