HackingStolen CredentialsTargetedPIIIDENTITY_BASICCREDENTIALSLowContained
Payactiv
bd_3157c62a8df34b92 · schema v1 · pii pii-v1
Full breach record for Payactiv →Payactiv, Inc. notified Vermont consumers of a cybersecurity incident where an unauthorized actor viewed personal information, including names, addresses, and potentially credentials. The breach was identified on September 12, 2025. Payactiv engaged third-party experts, notified law enforcement, and is offering credit monitoring services.
Vermont clock✓ VT AG ≤14 bday18 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_7e085442c1731a30New Hampshire State AGfiled 2025-09-29(1d gap)Verified
- bd_e3ea6aa0a8094db5Montana State AGfiled 2025-09-29(1d gap)Candidate
- bd_69970be9b9ebe336Indiana State AGfiled 2025-09-25(5d gap)Verified
- bd_384bdccd7645f4e1Washington State AGfiled 2025-10-11(11d gap)Verified by operator
Show 4 more filings ↓Show fewer ↑up to 99d gap
- bd_3ce26a4c298b1b78Oregon State AGfiled 2025-10-11(11d gap)Verified by operator
- bd_cba3b5443bba44b3Maine State AGfiled 2025-10-11(11d gap)Verified by operator
- bd_f8b2d1de52f6d894California State AGfiled 2025-10-11(11d gap)Verified
- bd_e018df5178963fbcTexas State AGfiled 2026-01-07(99d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-09-30-payactiv-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 30, 2025
- Raw hash
- 38e1b5f563e19ee205177bee1f778543a3739a1db62c208aad91f578b49fc27b
Reporting entity
- Name
- Payactivnorm: payactiv
- Domain
- payactivapp.com
Victim entity
- Name
- Payactivnorm: payactiv
- Domain
- payactivapp.com
Incident
- Discovered
- Sep 12, 2025
- Materiality determined
- —
- Notification sent
- Oct 30, 2025
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 18 days(18 days from discovery to filing)
- Compliance flags
- VT AG ≤14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.