Gap Inc.
ent_38df2050f1dabf3e82e7bc58
Disclosures
13
State AG · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
2,100
as filed · State AG HI
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Gap Inc.
- Normalized
- gap— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- 0000039911
- Domain
- gapinc.com
Disclosure history (13)newest first
- Massachusetts State AGas reporting2025-12-03
Gap International, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-12-03. 11 Massachusetts residents were affected.
- New Hampshire State AGas reporting2025-12-01
Gap International, Inc. notified the NH Attorney General of a data security incident affecting 2 New Hampshire residents. On July 22, 2025, the company experienced a network disruption and initiated an investigation. Independent cybersecurity experts were engaged. The investigation determined that certain files may have been accessed or acquired without authorization. A comprehensive review concluded on October 29, 2025, that personal information, including names, Social Security numbers, driver's license/state ID numbers, medical information, and health insurance information, was contained in the affected data. Notices were sent to affected residents on November 28, 2025. The company is providing credit monitoring and fraud assistance services.
- New Hampshire State AGas victim2022-12-08
Gap Inc. reported an insider misuse incident involving one New Hampshire resident. A customer service representative misused a customer's credit card information for two unauthorized transactions totaling $261. The incident was discovered on November 11, 2022, when the customer reported the misuse. The employee was terminated, and the company provided 24 months of credit monitoring to the affected individual.
- Massachusetts State AGas victim2018-03-02
GAP Inc reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-03-02. 17 Massachusetts residents were affected. The report records the breach type as paper.
- Massachusetts State AGas victim2016-02-09
Gap Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2016-02-09. 203 Massachusetts residents were affected. The report records the breach type as paper.
- Massachusetts State AGas victim2015-12-28
Gap Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2015-12-28. 3 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2015-10-13
Gap Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2015-10-13. 2 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2015-10-05
Gap Inc. notified NH AG of an insider incident where a store associate stole one NH resident's credit card info on Sept 17, 2015. Gap investigated, terminated the employee, notified law enforcement, and provided 1 year of credit monitoring to the victim.
- New Hampshire State AGas victim2010-10-04
Gap Inc. notified New Hampshire AG of an insider incident where a temporary call center worker accessed customer name, credit card number, and CVV for 2 NH residents. Notification sent Oct 4, 2010. Law enforcement contacted. 12 months credit monitoring offered.
- Massachusetts State AGas victim2010-01-25
Gap Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2010-01-25. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2010-01-07
Gap Inc. ("Gap") reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2010-01-07. 12 Massachusetts residents were affected. The report records the breach type as paper.
- Hawaii State AGas victim2009-09-28
Gap Inc. reported a data breach to the Hawaii Office of Consumer Protection. The office was notified on 2009/09.28. Breach type: Stolen Laptops, Computers & Equipment. 2,100 Hawaii residents were affected. Recovered from the Internet Archive after the notice was removed from the OCP table.
- Massachusetts State AGas victim2008-06-02
Gap, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2008-06-02. 18 Massachusetts residents were affected. The report records the breach type as paper.