HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
AmpUp
bd_7296064165221cde · schema v1 · pii pii-v1
Full breach record for AmpUp →AmpUp, Inc. experienced unauthorized access to its Stripe online payment platform on October 25, 2025. An unauthorized user leveraged a Stripe API Key to initiate fraudulent financial transactions. The incident impacted customer names and financial account information. AmpUp reversed transactions, rotated passwords, and engaged forensic investigators.
Vermont clock⏱ VT AG >14 bday8 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_1ce574c0effd870cIndiana State AGfiled 2025-12-22Verified
- bd_ee2946366e9c992aMaine State AGfiled 2025-12-22Candidate
- bd_b705ab0a7d335a2fNew Hampshire State AGfiled 2025-12-29(7d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-12-22-ampup-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 22, 2025
- Raw hash
- c595889dcde004cbbad6e25f408ded1dca581102936d3f6b1409b9fee2cece05
Reporting entity
- Name
- AmpUpnorm: ampup
- Domain
- ampup.ai
Victim entity
- Name
- AmpUpnorm: ampup
- Domain
- ampup.ai
Incident
- Discovered
- Oct 25, 2025
- Materiality determined
- —
- Notification sent
- Dec 22, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 8 weeks(58 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.