Gravity Payments, Inc.
bd_3da9b854cc85c057 · schema v1 · pii pii-v1
Full breach record for Gravity Payments, Inc. →Gravity Payments, Inc. notified the New Hampshire Attorney General of a data security incident affecting 4 NH residents. On or around August 22, 2025, an unknown actor exploited a vulnerability in a third-party CRM software to access files containing names and Social Security numbers. Gravity engaged cybersecurity experts, notified law enforcement, revoked third-party access, and mailed notifications on February 4, 2026, offering 12 months of identity protection.
J jump to incidentP pin to compareR raw source
Incident timeline
Aug 22, 2025
Begins
Feb 4, 2026
Filed
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- Indiana State AGbd_6e88a223a7c3669a2026-02-04Candidate
- Nebraska State AGbd_77941f9c91b544c72026-02-04Verified
- Massachusetts State AGbd_866480be2b95c0462026-02-04Verified
- Maine State AGbd_96eadfe6168c41092026-02-04Verified
Show 2 more filings ↓Show fewer ↑
- Vermont State AGbd_da75719f3caa78112026-02-04Verified
- Washington State AGbd_e0e4a5b9da0c668d2026-02-04Verified
Filing propagation · 7 filings · 7 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.