DisclosureLens
HackingTechnologyFinancial ServicesInformationStolen CredentialsCustomer Data InvolvedWire FraudIdentity (basic)Financial accountLowContained

AmpUp

bd_7296064165221cde · schema v1 · pii pii-v1

Severity

Low

Discovered

Oct 25, 2025

Filed

Dec 22, 2025

To disclose

8 weeks

Affected

Not disclosed

Linked

5 filings

Confidence

65%
Full breach record for AmpUp

AmpUp, Inc. experienced unauthorized access to its Stripe online payment platform on October 25, 2025. An unauthorized user leveraged the company's Stripe API Key to initiate fraudulent financial transactions associated with customer accounts. AmpUp detected the incident on the same day, reversed the transactions, rotated passwords, and implemented additional access controls. Affected data includes full names and financial account information. No specific count of affected individuals was disclosed.

Vermont clock VT AG >14 bday8 weeks discovery → filing

Incident timeline

discovery → filing · 8 weeks / 58 days

Oct 25, 2025

Begins

Oct 25, 2025

Discovered

Dec 22, 2025

Filed

vs. sector median

10 wks faster

This filing is one of 5 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (4) · sorted by filing gap

Filing propagation · 5 filings · 5 states

View merged incident ↗
Indiana State AGDec 22 · first
Maine State AGDec 22 · first
Vermont State AGDec 22 · first · this page

Pattern: first filing Dec 22 (IN), last Dec 29 (NH) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.