Gateways Community Services
ent_cf6455146f473dceebc56dde
Disclosures
3
State AG · 3 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
689
as filed · State AG NH
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Gateways Community Services
- Normalized
- gateways community— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (3)newest first
- ⛰️New Hampshire State AGas victim2026-05-05
Gateways Community Services, a New Hampshire nonprofit, notified the NH Attorney General of a cybersecurity incident discovered on February 2, 2026. The breach resulted from a phishing email that compromised an employee's email account, exposing Form W-2 data (names, addresses, SSNs, tax withholdings) for 689 individuals, including 627 NH residents. Gateways secured the account, engaged forensic investigators, implemented MFA and enhanced training, and offered 12 months of credit monitoring.
- 🦞Maine State AGas victim2026-05-05
Gateways Community Services, a non-profit based in Nashua, NH, filed a Maine AG data breach notice reporting a cyber incident occurring and discovered on 2/2/2026, affecting 689 individuals total (15 Maine residents). The breach description was reported as 'Other' and the specific data elements compromised were not enumerated in this filing. Written notifications were sent on 5/5/2026, and 12-24 months of TransUnion identity theft protection services were offered. The notice letter (ME_AG_Notice_of_Cyber_Incident_-_Gateways.pdf) was referenced but its content not included in this extraction.
- 🏛️Massachusetts State AGas victim2026-05-01
Gateways Community Services notified Massachusetts residents on May 5, 2026, of a data security incident involving unauthorized access to personal information. The breach exposed W-2 forms containing names, addresses, Social Security numbers, and financial account data. Gateways engaged outside experts, enhanced IT security training, implemented MFA for VPN access, and updated policies. Affected individuals were offered 24 months of complimentary credit monitoring and fraud assistance through Cyberscout (a TransUnion company).