MalwareRansomwareData EncryptedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Gas Express LLC
bd_ef60d379f4614672 · schema v1 · pii pii-v1
Full breach record for Gas Express LLC →Gas Express LLC, headquartered in Atlanta, GA, notified the Maryland Attorney General of a cybersecurity incident occurring on May 20, 2024. An unauthorized actor encrypted systems (ransomware), disrupting access. The investigation determined that personal information, including names, driver's license numbers, and Social Security numbers, was impacted. One Maryland resident was notified on January 13, 2025. Gas Express engaged cybersecurity experts and offers credit/identity monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376183.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 13, 2025
- Raw hash
- 2494e02a4d6fb3e4e2034059f53658e616da3ab29bdbc7b307dbd9db0cd3d72a
Reporting entity
- Name
- Constangy, Brooks, Smith & Prophete, LLPnorm: constangy brooks smith prophete
Victim entity
- Name
- Gas Express LLCnorm: gas express
Incident
- Discovered
- Dec 10, 2024
- Materiality determined
- —
- Notification sent
- Jan 13, 2025
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Maryland Attorney General
Compliance
- Time to disclose
- 48 weeks(338 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.