Gravity Payments, Inc.
bd_77941f9c91b544c7 · schema v1 · pii pii-v2
Full breach record for Gravity Payments, Inc. →Gravity Payments, Inc. notified Nebraska residents of a data security incident occurring on or around August 22, 2025. A third-party service provider's software vulnerability allowed an unknown actor to access Gravity's CRM files. The investigation, completed January 15, 2026, confirmed that customer names and additional personal information may have been affected. Gravity secured systems, revoked third-party access, notified law enforcement, and offered credit monitoring services.
J jump to incidentP pin to compareR raw source
Incident timeline
Aug 22, 2025
Begins
Aug 22, 2025
Discovered
Feb 4, 2026
Filed
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- New Hampshire State AGbd_3da9b854cc85c0572026-02-04Verified
- Indiana State AGbd_6e88a223a7c3669a2026-02-04Candidate
- Massachusetts State AGbd_866480be2b95c0462026-02-04Verified
- Maine State AGbd_96eadfe6168c41092026-02-04Verified
Show 2 more filings ↓Show fewer ↑
- Vermont State AGbd_da75719f3caa78112026-02-04Verified
- Washington State AGbd_e0e4a5b9da0c668d2026-02-04Verified
Filing propagation · 7 filings · 7 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.