United States House of Representatives
Incident posture
Linked entities
- Victim
- United States House of Representatives
- Threat actors
- 0 actors
- Sources
- 2 sources
Timeline
Summary
A company operating around 150 gas stations under the Handi Plus and Handi Stop brands in Texas suffered a data breach that exposed the personal data of more than 377,000 individuals. The threat actor gained initial access through a successful phishing attack and remained undetected within the company's IT systems for roughly ten days before being discovered in late September. During that time, the attacker stole sensitive personal information—including Social Security numbers, driver's license numbers, contact details, and names—and then deployed ransomware that encrypted portions of the company's IT estate. The company restored its systems using known-safe backups rather than paying a ransom, and no ransomware group has publicly claimed responsibility for the intrusion. The breach was disclosed to affected individuals and regulators months after the incident, prompting legal scrutiny over the delayed notification.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In late September 2025, Gulshan Management Services, Inc., the operator of approximately 150 Handi Plus and Handi Stop gas stations and convenience stores across Texas, detected unauthorized access to its IT systems. The breach was the result of a successful phishing attack that allowed an external threat actor to gain entry into the company's network. According to a subsequent filing with the Maine Attorney General's Office, the attacker maintained access to Gulshan's environment for approximately ten days before being discovered. During this window of undetected access, the threat actor was able to move through the company's IT estate, exfiltrate personal data belonging to customers, and ultimately deploy ransomware that encrypted portions of the company's files. The specific phishing vector used to compromise the initial perimeter was not disclosed in detail, but the intrusion is characterized as having originated from this single point of credential or access-based compromise.
The scope of the data exposure ultimately affected 377,082 individuals, based on the count of distinct sets of customer data identified during the investigation. The personal information compromised in the incident included full names, contact information, Social Security numbers, and driver's license numbers. This combination of data types represents a significant risk for identity theft and fraud for those impacted. The attacker was able to access and remove this information prior to the deployment of the ransomware payload, indicating that data theft was an objective alongside the disruptive encryption of systems. The timeline of the attack, from initial phishing compromise through data theft and ransomware deployment, was completed within roughly a ten-day period before the unauthorized activity was identified by the company.
Once the breach was detected in late September 2025, Gulshan initiated an investigation to determine the scope of the intrusion and the data that had been accessed or stolen. The company worked to expel the threat actor from its environment and assess the damage caused by both the data exfiltration and the ransomware encryption. Notably, no ransomware group publicly claimed responsibility for the attack during the period covered by the available reporting. Rather than paying a ransom to obtain a decryption key, Gulshan elected to restore its systems using what it described as "known-safe backups," indicating that the company maintained offline or otherwise protected backup copies that were not affected by the encryption event. This decision to rebuild from backups rather than negotiate with the attackers allowed Gulshan to resume operations without engaging with the threat actor.
Despite the company having detected the incident in late September 2025, public disclosure to affected customers did not occur until several months later, in early January 2026. This delay in notification became a focal point of legal scrutiny. The law firm Schubert Jonckheer and Kolbe publicly indicated that the company likely violated state and federal law by waiting so long to inform impacted individuals of the exposure of their personal data. The law firm announced that it was preparing a class action lawsuit against Gulshan and encouraged anyone who received a breach notice to join the legal action. Under typical U.S. state data breach notification statutes, companies are required to notify affected residents within a defined period after discovery of a breach, and the multi-month gap between detection and disclosure raised questions about Gulshan's compliance with these requirements. The exact regulatory exposure and the specific state laws cited as potentially violated were not detailed in the available reporting.
In response to the breach, Gulshan Management Services began providing the standard remediation offering commonly extended in such incidents: one year of identity monitoring services for individuals whose personal data was exposed. This service is intended to help affected customers detect potential misuse of their Social Security numbers, driver's license numbers, and other sensitive information. Beyond the identity monitoring offering, the available reporting did not detail additional specific remediation steps taken by the company, such as password resets, credential changes, or technical hardening measures applied to prevent recurrence. The company also did not publicly attribute the attack to a particular threat actor or group, and the phishing-based initial access vector was not further specified in terms of the specific lure or target employee involved.
The incident at Gulshan Management Services occurred against a broader backdrop of ransomware activity targeting small and mid-sized businesses and their backup infrastructure. The attack pattern observed at Gulshan, in which a threat actor gains initial access, conducts reconnaissance and data theft, and then deploys ransomware, mirrors tactics commonly reported across the industry. The use of phishing as the initial access vector, followed by the encryption of files, is consistent with the operational patterns of established ransomware groups, although no specific affiliation was claimed in this case. The decision by Gulshan to restore from backups rather than pay a ransom is consistent with recommended practices and allowed the company to avoid funding criminal operations. However, the data theft that occurred prior to encryption means that affected individuals face ongoing risk of identity-related fraud regardless of the restoration of operational systems. The delayed notification and subsequent class action activity represent the primary legal and reputational consequences documented in the available reporting.
Sources
Sources available to members: 2 sources.