HomeNewsBreachesAbout
Account
gap-salesforce-2025

Gap Breach

Oct 10, 2025

224,000 rows

Added on Oct 11, 2025

Search the Leak

Email
Full Name
Phone Number

What happened in the Gap Breach?

DataBreach.com Team Β· October 10th 2025, 8:00 pm EDT

Just before midnight on October 10'th, 2025 (11:59 p.m. ET), the group calling itself Scattered LAPSUS$ Hunters published what it claimed was a Gap Inc. dataset, following days of public ransom countdowns and extortion demands on its leak site. The group alleged that the data was taken from Gap’s Salesforce environment, as part of a broader 2025 campaign exploiting Salesforce-connected systems.

Our independent parse confirmed 256,200 unique email addresses, 152,100 phone numbers, and 146,100 home addresses contained in the leaked dataset. The data structure is consistent with Salesforce PersonAccount exports, featuring customer or contact records, system metadata, and loyalty account fields.

As of publication, Gap Inc. has not confirmed any breach, and the authenticity or origin of the dataset remains unverified.


Breach Unveiled

Early October 2025: Gap Inc. appears on the Scattered LAPSUS$ Hunters leak site alongside other alleged Salesforce clients.

October 10, 2025: The group issues a public ransom deadline, threatening full release if no payment is made.

October 11, 2025 (11:59 p.m. ET): Countdown expires; the group posts the full archive under Gap’s name.

As of this writing, Gap has made no public statement, and no data-breach notifications or regulatory filings appear on state or federal portals.


About the Threat Actor

Scattered LAPSUS$ Hunters emerged in mid-2025, positioning itself as a spiritual successor to LAPSUS$. The group runs a public leak portal featuring ransom countdowns and payment deadlines, and when demands are ignored, it posts full datasets.

Unlike encryption-based ransomware groups, their operations focus on data theft, extortion, and public exposure.


The Bigger Picture

The Gap posting is the latest in a string of Salesforce-linked extortion cases throughout 2025, joining leaks naming Albertsons, Qantas, and others. The recurring structure and metadata across these dumps underscore potential systemic risks within shared CRM and SaaS integrations.

Until Gap Inc. or Salesforce confirm or deny the compromise, the scope, authenticity, and impact of the leaked data remain uncertain.
DataBreach.com has indexed and anonymized the dataset for monitoring and research transparency.


Data found in the breach

🧍 Personal Information

  • Full name - βœ… Present
  • Record type (PersonAccount) - βœ… Present
  • Gender - β›” Empty
  • Birthdate / age - β›” Empty

πŸ“§ Contact Information

  • Email address - βœ… Present
  • Phone number - βœ… Present
  • Mailing address (street, city, state, ZIP, country) - βœ… Present
  • Shipping address - βœ… Present
  • Country - βœ… Present
  • Alternate phone or email - β›” Empty

πŸ’³ Account & Loyalty Data

  • Customer account ID - βœ… Present
  • External customer ID - βœ… Present
  • Registration date - βœ… Present
  • Rewards and loyalty program information - βœ… Present (includes points balance, tier, and value)
  • Reward tier (US/CA) - βœ… Present
  • Fraud status - βœ… Present (β€œBlue”)
  • Reward points fields - βœ… Present (including active, pending, and value in USD)
  • Loyalty email - β›” Empty

🏒 Company / System Fields

  • Store primary ID - βœ… Present
  • Market code - βœ… Present (β€œUS”)
  • Brand code - βœ… Present (β€œBR”)
  • Owner profile / agent - βœ… Present
  • Ownership flags - βœ… Present (e.g., hasNoOwner__c: true)

βš™οΈ System Metadata

  • Record IDs (AccountId, ContactId) - βœ… Present
  • Record creation date - βœ… Present
  • Record modification date - βœ… Present
  • SystemModstamp - βœ… Present
  • Created by / modified by IDs - βœ… Present
  • Record type ID - βœ… Present
  • Photo URL - βœ… Present
  • Sync status and timestamps - βœ… Present

πŸ’¬ Marketing & Communication

  • Email opt-out flags - β›” Empty
  • Direct marketing / consent fields - β›” Empty

πŸ“Š Activity & Visit Metrics

  • Total visits - βœ… Present (0.0)
  • Total time - βœ… Present (0.0)
  • Starred flag - βœ… Present (false)

For media inquiries, contact us at contact@databreach.com