Gravity Payments, Inc.
ent_723281d50d2f78d4
Disclosures
7
State AG · 7 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
22,278
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Gravity Payments, Inc.
- Normalized
- gravity payments— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- gravitypayments.com
Disclosure history (7)newest first
- New Hampshire State AGas victim2026-02-04
Gravity Payments, Inc. notified the New Hampshire Attorney General of a data security incident affecting 4 NH residents. On or around August 22, 2025, an unknown actor exploited a vulnerability in a third-party CRM software to access files containing names and Social Security numbers. Gravity engaged cybersecurity experts, notified law enforcement, revoked third-party access, and mailed notifications on February 4, 2026, offering 12 months of identity protection.
- Indiana State AGas victim2026-02-04
Gravity Payments Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2025-08-22 and was reported on 2026-02-04. 19 Indiana residents were affected. 22,278 individuals affected in total.
- Nebraska State AGas victim2026-02-04
Gravity Payments, Inc. notified Nebraska residents of a data security incident occurring on or around August 22, 2025. A third-party service provider's software vulnerability allowed an unknown actor to access Gravity's CRM files. The investigation, completed January 15, 2026, confirmed that customer names and additional personal information may have been affected. Gravity secured systems, revoked third-party access, notified law enforcement, and offered credit monitoring services.
- Massachusetts State AGas victim2026-02-04
Gravity Payments, Inc., a credit card processing and financial services company, notified Massachusetts residents of a data security incident involving a third-party service provider. The incident may have exposed names and other personal information. Gravity secured its systems, revoked the third party's access, and notified law enforcement. The company is offering credit monitoring and identity restoration services through Experian.
- Maine State AGas victim2026-02-04
Gravity Payments, Inc. reported an external system breach (hacking) occurring between August 12-23, 2025, discovered on August 22, 2025. An unknown actor accessed files in Gravity's CRM software via a third-party service provider vulnerability. Approximately 2,278 individuals were affected, including 14 Maine residents. The incident involved basic PII (names). Gravity secured systems, revoked vendor access, notified law enforcement, and offered 12 months of credit monitoring.
- Vermont State AGas victim2026-02-04
Gravity Payments, Inc. notified consumers that an unknown actor gained access to files in its customer relationship management software via a vulnerability in a third-party service provider's software on or around August 22, 2025. The incident affected personal information including names and other data. Gravity engaged cybersecurity experts, secured systems, revoked third-party access, and notified law enforcement. The investigation concluded on January 15, 2026. No evidence of misuse was found. Credit monitoring services are being offered.
- Washington State AGas victim2026-02-04
Gravity Payments, Inc. reported a cyberattack in Washington where an unknown actor accessed CRM files via a third-party vendor's software vulnerability. Incident occurred Aug 12-23, 2025; discovered Aug 22, 2025. 677 Washington residents affected. Data involved: names. Response included system security, revoking vendor access, law enforcement notification, and credit monitoring offers.