MalwareRansomwarePhishingStolen CredentialsRansom DemandedData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedMulti-Stage ChainPIIIDENTITY_BASICEMPLOYMENTLowContained
GATES CORPORATION
bd_92bdf5efe17f3c18 · schema v1 · pii pii-v1
Full breach record for GATES CORPORATION →Gates Corporation notified the New Hampshire Attorney General of a ransomware attack on February 11, 2023. The attacker gained access via spoofed emails (phishing). On April 30, 2023, Gates discovered personal information, including employee HR records, was exfiltrated. 68 New Hampshire residents were affected. Gates restored systems from backups without paying ransom and offered Kroll identity monitoring services.
Leak gap clock⏱ Leak >90d10 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
A leak claim by black_basta about this victim predates this filing by 146 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (2)
- bd_7cb93dc1a3353de6Leak Siteblack_bastafiled 2023-04-27(71d gap)Verified
- bd_0847fd8167e89d5dLeak Siteblack_bastafiled 2023-02-11(146d gap)Verified by operator
Regulatory filings (2) · sorted by filing gap
- bd_1043e7dc1792e8ebVermont State AGfiled 2023-07-07Verified by operator
- bd_112bce4c5e6bd787Maine State AGfiled 2023-07-07Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/gates-corporation-20230707.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 7, 2023
- Raw hash
- e195865604c4d7899ccd1b1c1a449fc79a05c0aee89a4bd1c8769a40fd301ce1
Reporting entity
- Name
- GATES CORPORATIONnorm: gates
- Domain
- gates.com
Victim entity
- Name
- GATES CORPORATIONnorm: gates
- Domain
- gates.com
Incident
- Discovered
- Apr 30, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 68
- Data types
- PIIIDENTITY_BASICEMPLOYMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1566.002 Spearphishing LinkT1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 10 weeks(68 days from discovery to filing)
- Compliance flags
- Leak >90d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.