AmpUp
bd_7296064165221cde · schema v1 · pii pii-v1
Full breach record for AmpUp →AmpUp, Inc. experienced unauthorized access to its Stripe online payment platform on October 25, 2025. An unauthorized user leveraged the company's Stripe API Key to initiate fraudulent financial transactions associated with customer accounts. AmpUp detected the incident on the same day, reversed the transactions, rotated passwords, and implemented additional access controls. Affected data includes full names and financial account information. No specific count of affected individuals was disclosed.
J jump to incidentP pin to compareR raw source
Incident timeline
Oct 25, 2025
Begins
Oct 25, 2025
Discovered
Dec 22, 2025
Filed
vs. sector median
10 wks faster
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Indiana State AGbd_1ce574c0effd870c2025-12-22Verified
- Maine State AGbd_ee2946366e9c992a2025-12-22Candidate
- Massachusetts State AGbd_58cdd81ffa637dbf2025-12-23 · +1dVerified
- New Hampshire State AGbd_b705ab0a7d335a2f2025-12-29 · +7dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Pattern: first filing Dec 22 (IN), last Dec 29 (NH) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.