Gravity Payments, Inc.
bd_da75719f3caa7811 · schema v1 · pii pii-v1
Full breach record for Gravity Payments, Inc. →Gravity Payments, Inc. notified consumers that an unknown actor gained access to files in its customer relationship management software via a vulnerability in a third-party service provider's software on or around August 22, 2025. The incident affected personal information including names and other data. Gravity engaged cybersecurity experts, secured systems, revoked third-party access, and notified law enforcement. The investigation concluded on January 15, 2026. No evidence of misuse was found. Credit monitoring services are being offered.
J jump to incidentP pin to compareR raw source
Incident timeline
Aug 22, 2025
Begins
Feb 4, 2026
Filed
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- New Hampshire State AGbd_3da9b854cc85c0572026-02-04Verified
- Indiana State AGbd_6e88a223a7c3669a2026-02-04Candidate
- Nebraska State AGbd_77941f9c91b544c72026-02-04Verified
- Massachusetts State AGbd_866480be2b95c0462026-02-04Verified
Show 2 more filings ↓Show fewer ↑
- Maine State AGbd_96eadfe6168c41092026-02-04Verified
- Washington State AGbd_e0e4a5b9da0c668d2026-02-04Verified
Filing propagation · 7 filings · 7 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.