Cyber Incident Victim: Gulshan Management Services, Inc.
Date:
Sep 2025
Location:
United States of America
Summary
Gulshan ManagementServices, Inc., which operates roughly 150 Handi Plus and Handi Stop gas stations and convenience stores in Texas, detected unauthorized access to its IT systems after a successful phishing attack, leading to a ransomware deployment that encrypted files and exposed personal data of about 377,000 individuals, including names, Social Security numbers, contact details, and driver’s license numbers. The company restored operations using known‑safe backups and did not pay a ransom, while no ransomware group has claimed responsibility; the delayed notification has prompted a class‑action lawsuit alleging violations of state and federal data‑breach laws.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
In late September 2025, Gulshan Management Services, Inc. detected unauthorized access to its IT systems. The intrusion began with a successful phishing attack that allowed the threat actor to gain entry to the network. The attacker remained undetected for approximately ten days before being identified. During this period, the threat actor exfiltrated personal data and deployed ransomware that encrypted portions of the company's IT estate.

Gulshan reported that the breach exposed 377,082 sets of customer information. The compromised data included names, social security numbers, contact details, and driver’s license numbers. The affected individuals were customers of the Handi Plus and Handi Stop gas station brands, which Gulshan operates across roughly 150 locations in Texas. No ransomware group has publicly claimed responsibility for the attack.
Following detection, Gulshan restored its systems using known-safe backups, indicating a decision to rebuild rather than pay a ransom. The company began providing affected customers with a year of identity monitoring services. Gulshan has notified impacted customers of the breach and is offering the monitoring assistance. A law firm, Schubert Jonckheer and Kolbe, stated that Gulshan likely violated state and federal notification laws by delaying disclosure, and is preparing a class action lawsuit on behalf of impacted individuals.
