MalwarePhishingRansomwareData EncryptedMulti-Stage ChainIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Gulshan Management Services
bd_4d1d56b0a51c0c71 · schema v1 · pii pii-v1
Full breach record for Gulshan Management Services →Gulshan Management Services, Inc. notified consumers of a data breach discovered on September 27, 2025, resulting from a phishing attack on September 17, 2025. The incident involved unauthorized access and the deployment of malicious software that encrypted portions of the network. Affected data included names, contact info, SSNs, and driver's license numbers. GMS engaged Kroll for credit monitoring and rebuilt systems.
Vermont clock✗ VT AG >45 bday14 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_78a97382f455f091Indiana State AGfiled 2026-01-05Candidate
- bd_a465700a822b3c12New Hampshire State AGfiled 2026-01-05Verified
- bd_217671fec1634ed9Maine State AGfiled 2026-01-06(1d gap)Verified
- bd_24f2f711ac332f95Iowa State AGfiled 2026-01-06(1d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 70d gap
- bd_62380f5de3719fcbSouth Carolina State AGfiled 2026-01-06(1d gap)Verified
- bd_98d92f168972093aTexas State AGfiled 2026-03-16(70d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2026-01-05-gulshan-management-services-data-breach-notices-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 5, 2026
- Raw hash
- 37a24866e91f92f9511cc0a17f19e48a39f28aca54b7cfee247420f9f103d1fb
Reporting entity
- Name
- Gulshan Management Servicesnorm: gulshan management
Victim entity
- Name
- Gulshan Management Servicesnorm: gulshan management
Incident
- Discovered
- Sep 27, 2025
- Materiality determined
- —
- Notification sent
- Jan 5, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified regulatory authorities in relevant jurisdictions
- Initial access
- phishing_link
Compliance
- Time to disclose
- 14 weeks(100 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.