Data breach
Gap
- Records
- 224,000
- Breach date
- 10 October 2025Estimated
- Added
- 11 October 2025
What was exposed
4 types of data
- Email addresses1
- Names1
- Home addresses1
- Phone numbers1
About this breach
Gap Inc. appears among the victims named in a large 2025 extortion campaign that targeted customers of Salesforce, the customer relationship management platform. According to our investigation team, this listing covers about 224,000 rows of data attributed to Gap. Reporting from BleepingComputer, SecurityWeek, and Hackread describes a group calling itself Scattered Lapsus$ Hunters, linked by researchers to the ShinyHunters, Scattered Spider, and Lapsus$ crews, which stole data from Salesforce instances through social engineering and misused third-party connected apps rather than a flaw in Salesforce itself. Salesforce said its core platform was not compromised.
The group posted a leak site listing 39 companies it claimed to have hit, Gap among them, and demanded payment. When Salesforce refused to negotiate, the actors began publishing data for some victims. Hackread reports the Gap dataset was about 1 GB in JSON format and holds more than 224,000 records, uploaded on October 10, 2025. These figures come from the attackers' own leak portal, so they have not been independently confirmed by the company.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
October 3, 2025: Scattered Lapsus$ Hunters launched a data leak site listing 39 companies it claimed to have breached through Salesforce, including Gap, with an October 10 deadline to prevent disclosure, according to BleepingComputer.
October 7, 2025: Salesforce reportedly refused to negotiate or pay a ransom, as reported by SC Media.
October 10, 2025: SecurityWeek and Hackread reported that the group published datasets for several victims, including Gap, with the Gap data described as roughly 224,000 records.
What Information Was Compromised?
Our analysis found the following data types in this breach: Email, Name, Phone Number, Home Address.
Not every individual is affected by every type of data listed here.
Reporting on the campaign described customer contact records of the kind typically stored in Salesforce, including names, email addresses, phone numbers, and postal addresses. Because the material was published by the attackers and Gap has not published a detailed notice that we located, the exact fields and record counts for each person cannot be confirmed.
What Are the Potential Risks for Affected Individuals?
Targeted phishing that uses Gap branding, such as fake order confirmations, return notices, or rewards messages built around your real name, email, or phone number.
Smishing, or fraudulent text messages, since phone numbers are part of the exposed data.
Credential stuffing against other accounts if you reused passwords, even though passwords are not confirmed as part of this data.
Attempts to make scams more convincing by pairing your name with your home address.
What Should You Do If You Were Affected?
Treat unexpected Gap, Old Navy, Athleta, or Banana Republic messages about orders, returns, or rewards as suspicious unless they arrive through official channels. Go directly to the official website or app instead of clicking links.
Enable multi-factor authentication on your email and shopping accounts.
Change any passwords you have reused across sites, starting with your email account.
Be cautious with calls or texts referencing your account details. Knowing your name, phone number, and address does not make someone a legitimate company representative.
