HackingCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_BASICLowContained
Payactiv
bd_f8b2d1de52f6d894 · schema v1 · pii pii-v1
Full breach record for Payactiv →Payactiv, Inc. reported a cybersecurity incident where an unauthorized actor viewed information stored in its systems between April 3, 2025, and August 20, 2025. The company discovered the incident on August 19, 2025. Affected individuals received 12 months of complimentary credit monitoring and identity theft protection services.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_384bdccd7645f4e1Washington State AGfiled 2025-10-11Verified by operator
- bd_3ce26a4c298b1b78Oregon State AGfiled 2025-10-11Verified by operator
- bd_cba3b5443bba44b3Maine State AGfiled 2025-10-11Verified by operator
- bd_3157c62a8df34b92Vermont State AGfiled 2025-09-30(11d gap)Verified
Show 4 more filings ↓Show fewer ↑up to 88d gap
- bd_7e085442c1731a30New Hampshire State AGfiled 2025-09-29(12d gap)Verified
- bd_e3ea6aa0a8094db5Montana State AGfiled 2025-09-29(12d gap)Candidate
- bd_69970be9b9ebe336Indiana State AGfiled 2025-09-25(16d gap)Verified
- bd_e018df5178963fbcTexas State AGfiled 2026-01-07(88d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-612706
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 11, 2025
- Raw hash
- 9e8b1fbd53c0ab5ef6694ed48d3dd35ab5d2ebd5c5e3f1df37cbfb79a53961f4
Reporting entity
- Name
- Payactivnorm: payactiv
- Domain
- payactivapp.com
Victim entity
- Name
- Payactivnorm: payactiv
- Domain
- payactivapp.com
Incident
- Discovered
- Aug 19, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
Compliance
- Time to disclose
- 8 weeks(53 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.