HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Gravity Payments, Inc.
bd_3da9b854cc85c057 · schema v1 · pii pii-v1
Full breach record for Gravity Payments, Inc. →Gravity Payments, Inc. notified the New Hampshire Attorney General of a data security incident affecting 4 NH residents. On or around August 22, 2025, an unknown actor exploited a vulnerability in a third-party CRM software to access files containing names and Social Security numbers. Gravity engaged cybersecurity experts, notified law enforcement, revoked third-party access, and mailed notifications on February 4, 2026, offering 12 months of identity protection.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_6e88a223a7c3669aIndiana State AGfiled 2026-02-04Candidate
- bd_96eadfe6168c4109Maine State AGfiled 2026-02-04Verified
- bd_da75719f3caa7811Vermont State AGfiled 2026-02-04Verified
- bd_e0e4a5b9da0c668dWashington State AGfiled 2026-02-04Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/gravity-payments-20260204.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 4, 2026
- Raw hash
- ebfd7cb4c53cc5d1b3adaace63a910528be9a3fbdb3e1a1a8cd80c870bfc918b
Reporting entity
- Name
- Gravity Payments, Inc.norm: gravity payments
- Domain
- gravitypayments.com
Victim entity
- Name
- Gravity Payments, Inc.norm: gravity payments
- Domain
- gravitypayments.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Feb 4, 2026
- Affected individuals
- 4
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified Attorney General John Formella
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.