Gravity Payments, Inc.
bd_96eadfe6168c4109 · schema v1 · pii pii-v1
Full breach record for Gravity Payments, Inc. →Gravity Payments, Inc. reported an external system breach (hacking) occurring between August 12-23, 2025, discovered on August 22, 2025. An unknown actor accessed files in Gravity's CRM software via a third-party service provider vulnerability. Approximately 2,278 individuals were affected, including 14 Maine residents. The incident involved basic PII (names). Gravity secured systems, revoked vendor access, notified law enforcement, and offered 12 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Aug 12, 2025
Begins
Aug 22, 2025
Discovered
Feb 4, 2026
Filed
vs. sector median
+15 wks slower
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- New Hampshire State AGbd_3da9b854cc85c0572026-02-04Verified
- Indiana State AGbd_6e88a223a7c3669a2026-02-04Candidate
- Nebraska State AGbd_77941f9c91b544c72026-02-04Verified
- Massachusetts State AGbd_866480be2b95c0462026-02-04Verified
Show 2 more filings ↓Show fewer ↑
- Vermont State AGbd_da75719f3caa78112026-02-04Verified
- Washington State AGbd_e0e4a5b9da0c668d2026-02-04Verified
Filing propagation · 7 filings · 7 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.