HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Payactiv
bd_7e085442c1731a30 · schema v1 · pii pii-v1
Full breach record for Payactiv →Payactiv, Inc. notified the New Hampshire Attorney General of a cybersecurity incident affecting 54 NH residents. Unauthorized access occurred between April 3 and August 20, 2025. Payactiv discovered the incident on August 19, 2025, and began mailing notifications on September 29, 2025. Compromised data included names and Social Security numbers. Payactiv engaged third-party experts, notified law enforcement, and offered one year of credit monitoring.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_e3ea6aa0a8094db5Montana State AGfiled 2025-09-29Candidate
- bd_3157c62a8df34b92Vermont State AGfiled 2025-09-30(1d gap)Verified
- bd_69970be9b9ebe336Indiana State AGfiled 2025-09-25(4d gap)Verified
- bd_384bdccd7645f4e1Washington State AGfiled 2025-10-11(12d gap)Verified by operator
Show 4 more filings ↓Show fewer ↑up to 100d gap
- bd_3ce26a4c298b1b78Oregon State AGfiled 2025-10-11(12d gap)Verified by operator
- bd_cba3b5443bba44b3Maine State AGfiled 2025-10-11(12d gap)Verified by operator
- bd_f8b2d1de52f6d894California State AGfiled 2025-10-11(12d gap)Verified
- bd_e018df5178963fbcTexas State AGfiled 2026-01-07(100d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/payactiv-20250929.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 29, 2025
- Raw hash
- 25499d0f29a528a1f28ab64ba7d8db40dea705d24a434f1c7034ab052150a12a
Reporting entity
- Name
- Baker & Hostetler LLP (on behalf of Payactiv, Inc.)norm: baker hostetler llp on behalf of payactiv
Victim entity
- Name
- Payactivnorm: payactiv
- Domain
- payactivapp.com
Incident
- Discovered
- Aug 19, 2025
- Materiality determined
- —
- Notification sent
- Sep 29, 2025
- Affected individuals
- 54
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 6 weeks(41 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.