2026 Gravity Payments — 2,278 records (third-party CRM)
Data compromised
SSNs, names, financial info, banking info, DOB, addresses, government IDs, usernames, passwords, security questions
Technical writeup
Seattle-based credit card processor Gravity Payments disclosed breach Feb 5, 2026. Unknown actor exploited third-party CRM software vulnerability on Aug 22, 2025. Investigation completed Jan 15, 2026. Exposed: SSNs, names, financial/banking info, DOB, addresses, government IDs, usernames, passwords, security question answers. Affected individuals across Washington (677), Massachusetts (16), Maine (14), New Hampshire (4). Company revoked third-party access; 12 months Experian credit monitoring offered.
Root cause
Third-party CRM vulnerability exploitation