General Dynamics
ent_1dd99a18e630fcf8b31a0b04
Disclosures
1
State AG · 1 jurisdiction
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
37
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- General Dynamics
- Normalized
- general dynamics— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 9C1X8XOOTYY2FNYTVH06
- SEC EDGAR CIK
- 0000040533
- Domain
- gd.com
Disclosure history (1)newest first
Subsidiary disclosures (newest 10)filed by group companies
◈ These filings were made by or about subsidiaries of General Dynamics — not by General Dynamics itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- Texas State AGvia Gulfstream Services Corporation2026-05-11
Gulfstream Services, Inc. based in Houma, Louisiana, a business – retail or merchant entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-03-10 and reported on 2026-05-11. 328 Texas residents were affected. 1,017 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Driver’s License number;Government-issued ID number (e.g. passport, state ID card);Financial Information (e.g. account number, credit or debit card number);Medical Information;Date of Birth. Consumers were notified via U.S. Mail.
- GLOBALLeak Sitevia Gulfstream Services Corporation2026-02-13
- SINGAPORESingapore PDPCvia Jet Aviation (Asia Pacific) Pte. Ltd.2025-02-27
Background Jet Aviation (Asia Pacific) Pte Ltd (the “ Organisation ”) operates private jet charters for individuals and provides aircraft Maintenance, Repair and Overhaul (“ MRO ”) services. On 26 July 2024, the Organisation notified the Personal Data Protection Commission (the “ Commission ”) of unauthorised access to 5 of the Organisation’s email accounts containing personal data (the “ Incident ”). I nvestigations revealed that that the threat actor (“ TA ”) had likely gained access to the email accounts via spear phishing emails sent to specific employees. The TA had engineered the phishing emails to appear as legitimate requests for e-signatures from either trusted business partners or from within the Organisation. The TA used a cloud-based e-signature service, Adobe Acrobat Sign, to send documents containing a phishing link to the targeted employees. As the phishing link was contained within the document, the emails bypassed the Organisation’s security scans for malicious email content. The targeted employees were convinced on the authenticity of the emails as the emails also bore a legitimate sender email address from Adobe. After clicking on the link, the employees were directed to a phishing website which emulated the Microsoft Office logon page and displayed genuine email addresses associated with the Organisation. Believing that the website that they had been directed to was authentic, the targeted employees entered their Microsoft credentials and the necessary passwords and multi-factor authentication (“ MFA ”) tokens. The phishing website then employed a reverse proxy to relay this information to the genuine Microsoft website and intercepted the primary refresh tokens returned by the Microsoft website. With the intercepted tokens, the TA was able to bypass existing MFA and gain persistent access to the email accounts. The 5 affected email accounts contain
- New Hampshire State AGvia Jet Aviation (Asia Pacific) Pte. Ltd.2024-10-18
Jet Aviation (Asia Pacific) Pte. Ltd. experienced a business email compromise (BEC) incident where a threat actor gained unauthorized access to five email accounts to divert invoice payments. The company became aware of the incident on September 13, 2023. Although the primary motive was financial fraud, personal information of three New Hampshire residents may have been accessed. The company reset credentials, blocked malicious domains, and is offering credit monitoring.
- New Hampshire State AGvia Jet Aviation2021-02-16
Jet Aviation Flight Services, Inc. notified the NH AG of a data incident involving its third-party provider, Avianis. Unauthorized access occurred on Dec 5, 2020, discovered by Jet Aviation on Dec 23, 2020. 32 NH residents were affected. Data included passports, visas, driver's licenses, and credit card info. Notifications were sent via email and mail. Avianis addressed the vulnerability.
- California State AGvia Jet Aviation2021-02-10
Jet Aviation notified customers of a data incident involving its third-party scheduling software provider, Avianis. The incident, occurring on December 6, 2020, potentially compromised personally identifying information including passport, travel visa, and driver's license details. Jet Aviation offered complimentary identity monitoring services to affected customers. The cause was attributed to a vulnerability in the third-party system.
- Massachusetts State AGvia General Dynamics Information Technology2020-03-27
General Dynamics Information Technology (GDIT) reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-03-27. 3 Massachusetts residents were affected. The report records the breach type as paper.
- Indiana State AGvia General Dynamics Information Technology2020-03-09
General Dynamics Information Technology reported a data breach to the Indiana Attorney General. The breach occurred on 2020-01-17 and was reported on 2020-03-09. 3 Indiana residents were affected. 330 individuals affected in total.
- New Hampshire State AGvia General Dynamics Information Technology2019-01-03
General Dynamics Information Technology (GDIT) notified the New Hampshire Attorney General of a data breach involving a former employee who accessed consumer records between Oct 31 and Nov 13, 2018. Data included names, SSNs, DOBs, and addresses. 32 NH residents affected. Notifications sent Dec 28, 2018, with 24 months of identity theft protection.
- Montana State AGvia General Dynamics Information Technology2018-12-28
GDIT disclosed that a former employee accessed consumer records between Oct 31 and Nov 13, 2018. Data included names, SSNs, and DOBs. GDIT notified law enforcement and offered 24 months of identity theft protection. No specific count of affected individuals was provided.