HackingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Gap Inc.
bd_bb121efff65c0d2c · schema v1 · pii pii-v1
Full breach record for Gap Inc. →Gap International, Inc. notified the New Hampshire Attorney General of a data security event affecting two New Hampshire residents. On July 22, 2025, a network disruption occurred, leading to unauthorized access to files containing names and Social Security numbers. Gap engaged cybersecurity experts, determined the scope by October 29, 2025, and notified the two affected individuals on November 28, 2025. No evidence of misuse was found. Credit monitoring was provided.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/gap-international-20251201.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 1, 2025
- Raw hash
- 93445c0959b10df00b86dda5f7eb4d803069fdd4c55263ef8a3edfddf4dafd8b
Reporting entity
- Name
- Gap Inc.norm: gap
- Domain
- gapinc.com
Victim entity
- Name
- Gap Inc.norm: gap
- Domain
- gapinc.com
Incident
- Discovered
- Jul 22, 2025
- Materiality determined
- —
- Notification sent
- Nov 28, 2025
- Affected individuals
- 2
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General
Compliance
- Time to disclose
- 19 weeks(132 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.