HackingFinancial ServicesFinanceVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPIILowContained
Gravity Payments, Inc.
bd_96eadfe6168c4109 · schema v1 · pii pii-v1
Full breach record for Gravity Payments, Inc. →Gravity Payments (credit card processing) reported an unknown actor exploited a vulnerability in a third-party CRM provider's software to access Gravity customer files. Breach period: Aug 12-23, 2025; discovered Aug 22, 2025. Review completed Jan 15, 2026. 14 Maine residents among 2,278 total affected. Gravity revoked provider access, notified law enforcement, and offered 12 months Experian credit monitoring.
Maine clockDiscovered Aug 22, 2025 → Filed with AG Feb 4, 2026166d ✗ ME AG >90d24 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_3da9b854cc85c057New Hampshire State AGfiled 2026-02-04Verified
- bd_6e88a223a7c3669aIndiana State AGfiled 2026-02-04Candidate
- bd_da75719f3caa7811Vermont State AGfiled 2026-02-04Verified
- bd_e0e4a5b9da0c668dWashington State AGfiled 2026-02-04Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/ee90778a-e6bd-43d0-a5df-02439f5c8592.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 4, 2026
- Raw hash
- 1c648379c30a26b7c52c3023f31c41feb7d59a76829d6bd8c625b34991ef984f
Reporting entity
- Name
- Gravity Payments, Inc.norm: gravity payments
- Domain
- gravitypayments.com
- Industry
- Credit card processing and financial services
Victim entity
- Name
- Gravity Payments, Inc.norm: gravity payments
- Domain
- gravitypayments.com
- Industry
- Credit card processing and financial services
- Industry
- Financial Servicesllm
Incident
- Discovered
- Aug 22, 2025
- Materiality determined
- Jan 15, 2026
- Notification sent
- Feb 4, 2026
- Affected individuals
- 14
- Data types
- PII
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 24 weeks(166 days from discovery to filing)
- Compliance flags
- ME AG >90d · 166dME resident >60d · 166d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Aug 22, 2025→ Filed with AG: Feb 4, 2026166d 90 days ME AG >90d Maine Discovered: Aug 22, 2025→ Notified: Feb 4, 2026166d 60 days (analyst band; statutory cap is 30 days) ME resident >60d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.