Gulshan Management Services
ent_e8c4272bfa27eb5874b81a7b
Disclosures
10
State AG · 10 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
377,082
nationwide · State AG TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Gulshan Management Services
- Normalized
- gulshan management— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (10)newest first
- Texas State AGas victim2026-03-16
Gulshan Management Services, Inc. based in Sugar Land, Texas, a business – retail or merchant entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-09-27 and reported on 2026-03-16. 128,652 Texas residents were affected. 377,082 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Driver’s License number;Government-issued ID number (e.g. passport, state ID card);Financial Information (e.g. account number, credit or debit card number). Consumers were notified via U.S. Mail.
- Maine State AGas victim2026-01-06
Gulshan Management Services, Inc. reported a data breach affecting 377,082 individuals, including 54 Maine residents. The incident involved a phishing attack on September 17, 2025, leading to unauthorized access and deployment of malicious software that encrypted portions of the network. Compromised data included names, contact info, SSNs, and driver's license numbers. GMS contained the incident, rebuilt systems, and offered 12 months of Kroll identity monitoring.
- Iowa State AGas victim2026-01-06
Gulshan Management Services, Inc. reported a cybersecurity incident to the Iowa Attorney General on January 6, 2025. On or about September 27, 2025, an unknown threat actor encrypted GMS's network using Qilin ransomware following a successful phishing attack against an employee. GMS rebuilt systems from backups and engaged forensic investigators. Iowa residents' names, addresses, DOBs, SSNs, and driver's license numbers were compromised. GMS reset credentials, enhanced access controls, and provided credit monitoring to affected individuals.
- South Carolina State AGas victim2026-01-06
Gulshan Management Services, Inc. (GMS) disclosed a cybersecurity incident in South Carolina. On September 17, 2025, an unauthorized third party gained access via a phishing attack. The actor accessed servers hosting personal data (names, contact info, SSNs, driver's license numbers) and deployed ransomware encrypting portions of the network. GMS contained the incident, rebuilt systems using safe backups, reset credentials, and engaged Kroll for 12 months of identity monitoring. Law enforcement was notified.
- Massachusetts State AGas victim2026-01-06
Gulshan Management Services, Inc. (GMS), a business services company, notified the Massachusetts Attorney General of a data security incident where an unauthorized third party accessed personal information. Affected data included names, contact information, social security numbers, financial account numbers, and drivers' license numbers. GMS rebuilt compromised systems, reset credentials, and offered 24 months of identity monitoring via Kroll. No specific dates or affected counts were disclosed in the notice.
- Vermont State AGas victim2026-01-05
Gulshan Management Services, Inc. notified consumers of a data breach discovered on September 27, 2025, resulting from a phishing attack on September 17, 2025. The incident involved unauthorized access and the deployment of malicious software that encrypted portions of the network. Affected data included names, contact info, SSNs, and driver's license numbers. GMS engaged Kroll for credit monitoring and rebuilt systems.
- Indiana State AGas victim2026-01-05
Gulshan Management Services Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2025-09-17 and was reported on 2026-01-05. 6,011 Indiana residents were affected. 377,082 individuals affected in total.
- Nebraska State AGas victim2026-01-05
Gulshan Management Services, Inc. (GMS) disclosed a data breach in Nebraska discovered on September 27, 2025, resulting from a phishing attack on September 17, 2025. An unauthorized third party accessed systems, encrypted portions of the network with ransomware, and potentially accessed names, contact info, SSNs, and driver's license numbers. GMS contained the incident, rebuilt systems, reset credentials, engaged Kroll for 12 months of identity monitoring, and notified law enforcement.
- New Hampshire State AGas victim2026-01-05
Gulshan Management Services, Inc. reported a data breach to the New Hampshire Attorney General on January 5, 2025. The incident involved a phishing attack on September 17, 2025, leading to Qilin ransomware encryption of network portions. Approximately 4,403 New Hampshire residents were affected, with personal information including names, SSNs, and driver's license numbers exposed. GMS reset credentials, rebuilt systems from backups, and engaged forensic investigators and Kroll for credit monitoring.
- Illinois State AGas victim2026-01-01
GULSHAN MANAGEMENT SERVICES, INC. filed a data-breach notice with the Illinois Attorney General in January 2026 (case 26-01-702). The register records the breach as discovered on September 27, 2025. Personal information types reported: drivers license, financial account number, ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.