Gravity Payments, Inc.
bd_e0e4a5b9da0c668d · schema v1 · pii pii-v1
Full breach record for Gravity Payments, Inc. →Gravity Payments, Inc. reported a cyberattack in Washington where an unknown actor accessed CRM files via a third-party vendor's software vulnerability. Incident occurred Aug 12-23, 2025; discovered Aug 22, 2025. 677 Washington residents affected. Data involved: names. Response included system security, revoking vendor access, law enforcement notification, and credit monitoring offers.
J jump to incidentP pin to compareR raw source
Incident timeline
Aug 12, 2025
Begins
Aug 22, 2025
Discovered
Feb 4, 2026
Filed
vs. sector median
+15 wks slower
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- New Hampshire State AGbd_3da9b854cc85c0572026-02-04Verified
- Indiana State AGbd_6e88a223a7c3669a2026-02-04Candidate
- Nebraska State AGbd_77941f9c91b544c72026-02-04Verified
- Massachusetts State AGbd_866480be2b95c0462026-02-04Verified
Show 2 more filings ↓Show fewer ↑
- Maine State AGbd_96eadfe6168c41092026-02-04Verified
- Vermont State AGbd_da75719f3caa78112026-02-04Verified
Filing propagation · 7 filings · 7 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.