← Gulfstream Services

2026 Gulfstream Services Inc. — PLAY ransomware; oilfield services (TX AG: 250+ residents; Apr 10)

2026 250 records affected Share on X

Data compromised

PII, financial, tax, and some medical/insurance categories per state-notification summaries

Technical writeup

Gulfstream Services Inc., a Louisiana–headquartered oil and energy field services company (distinct from Gulfstream Aerospace), appeared in public breach reporting after the PLAY ransomware group posted a victim claim on its Tor leak site on February 22, 2026, alleging theft of business and employee-style materials. Regulatory-style summaries (e.g., Texas Attorney General consumer breach listings) cited an April 10, 2026 disclosure date with at least 250 Texas residents notified and described broad categories such as names, addresses, dates of birth, Social Security numbers, driver’s licenses, government IDs, financial account and card data, and some protected health and insurance information in composite filings. Full national victim counts were not uniformly published in early summaries; treat 250 as a minimum confirmed in one state filing.

Root cause

Ransomware / extortion (PLAY group claim per open-source reporting)

References