MisusePrivilege AbuseCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowResolved
Gap Inc.
bd_bd2c01963f211b35 · schema v1 · pii pii-v1
Full breach record for Gap Inc. →Gap Inc. reported an insider misuse incident involving one New Hampshire resident. A customer service representative misused a customer's credit card information for two unauthorized transactions totaling $261. The incident was discovered on November 11, 2022, when the customer reported the misuse. The employee was terminated, and the company provided 24 months of credit monitoring to the affected individual.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/gap-20221208.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 8, 2022
- Raw hash
- 01c358c7881ef0415ede1bd724f78d777c17c2bc580bac2f3f2c3efa15dec04b
Reporting entity
- Name
- Gap Inc.norm: gap
- Domain
- gapinc.com
Victim entity
- Name
- Gap Inc.norm: gap
- Domain
- gapinc.com
Incident
- Discovered
- Nov 11, 2022
- Materiality determined
- —
- Notification sent
- Nov 25, 2022
- Affected individuals
- 1
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Insider
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- InternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General's Consumer Protection & Antitrust Bureau
- Initial access
- insider_action
Compliance
- Time to disclose
- 27 days(27 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.