AmpUp
bd_ee2946366e9c992a · schema v1 · pii pii-v1
Full breach record for AmpUp →AmpUp, Inc. reported an unauthorized access to its Stripe online payment platform on October 25, 2025. An unauthorized user leveraged a Stripe API Key to initiate fraudulent financial transactions. The breach was discovered on November 17, 2025, after forensic investigation. Two Maine residents were affected. AmpUp reversed transactions, rotated passwords, and implemented additional access controls. Notification letters were sent on December 22, 2025.
J jump to incidentP pin to compareR raw source
Incident timeline
Oct 25, 2025
Begins
Nov 17, 2025
Discovered
Dec 22, 2025
Filed
vs. sector median
14 wks faster
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Indiana State AGbd_1ce574c0effd870c2025-12-22Verified
- Vermont State AGbd_7296064165221cde2025-12-22Verified
- Massachusetts State AGbd_58cdd81ffa637dbf2025-12-23 · +1dVerified
- New Hampshire State AGbd_b705ab0a7d335a2f2025-12-29 · +7dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Pattern: first filing Dec 22 (IN), last Dec 29 (NH) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.