HackingStolen CredentialsSupply Chain (3P Vendor)TargetedIDENTITY_BASICLowContained
Gravity Payments, Inc.
bd_da75719f3caa7811 · schema v1 · pii pii-v1
Full breach record for Gravity Payments, Inc. →Gravity Payments, Inc. notified Vermont consumers of a data breach occurring on or around August 22, 2025. An unknown actor accessed Gravity files via a vulnerability in a third-party CRM software provider's system. Affected data included names and other personal information. Gravity secured systems, revoked vendor access, notified law enforcement, and offered credit monitoring services.
Vermont clock✗ VT AG >45 bday24 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_3da9b854cc85c057New Hampshire State AGfiled 2026-02-04Verified
- bd_6e88a223a7c3669aIndiana State AGfiled 2026-02-04Candidate
- bd_96eadfe6168c4109Maine State AGfiled 2026-02-04Verified
- bd_e0e4a5b9da0c668dWashington State AGfiled 2026-02-04Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2026-02-04-gravity-payments-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 4, 2026
- Raw hash
- 9d6cfcab28e67ce3d6ee8a3587867eb701998c90eea566a3fecbfd7ba0ffb2b9
Reporting entity
- Name
- Gravity Payments, Inc.norm: gravity payments
- Domain
- gravitypayments.com
Victim entity
- Name
- Gravity Payments, Inc.norm: gravity payments
- Domain
- gravitypayments.com
Incident
- Discovered
- Aug 22, 2025
- Materiality determined
- Feb 4, 2026
- Notification sent
- Feb 4, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- supply_chain
Compliance
- Time to disclose
- 24 weeks(166 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.