HackingData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICBEHAVIORMETADATALowContained
GSPlatformCo Inc
bd_4ed66e6c4f37d2eb · schema v1 · pii pii-v1
Full breach record for GSPlatformCo Inc →GSPlatformCo Inc (operating as ANKA) notified the California AG of unauthorized access to a customer data storage system containing a snapshot of user data from April 2025. Exposed data included basic profile details (name, contact information, demographic data), account status, and basic transaction history. No passwords, payment card data, login tokens, or financial data were compromised. The company launched a security investigation, hardened its environment, and notified data protection authorities.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_9fb38cf7fb093047Washington State AGfiled 2026-01-12Verified
- bd_ae32ca57c4e89aefMaine State AGfiled 2026-01-12Verified
- bd_e571e074be5ee942New Hampshire State AGfiled 2026-01-12Verified
- bd_731ce90868a6c3cfIndiana State AGfiled 2026-01-11(1d gap)Candidate
Show 1 more filing ↓Show fewer ↑up to 19d gap
- bd_50c0e0a87c4629eaOregon State AGfiled 2026-01-31(19d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-616922
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 12, 2026
- Raw hash
- bb163d901ebc97361df0e87f20b6e73aca59e17d2b19073ee652680f8a9b3093
Reporting entity
- Name
- GSPlatformCo Incnorm: gsplatformco
- Domain
- anka.africa
Victim entity
- Name
- GSPlatformCo Incnorm: gsplatformco
- Domain
- anka.africa
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICBEHAVIORMETADATA
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1530 Data from Cloud Storage Object
- Threat actor
- External
- Regulator citations
- Notified the relevant data protection authorities, as required by law
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.