← Gravity Payments

2026 Gravity Payments — 2,278 records (third-party CRM)

2026 2.3K records affected Share on X

Data compromised

SSNs, names, financial info, banking info, DOB, addresses, government IDs, usernames, passwords, security questions

Technical writeup

Seattle-based credit card processor Gravity Payments disclosed breach Feb 5, 2026. Unknown actor exploited third-party CRM software vulnerability on Aug 22, 2025. Investigation completed Jan 15, 2026. Exposed: SSNs, names, financial/banking info, DOB, addresses, government IDs, usernames, passwords, security question answers. Affected individuals across Washington (677), Massachusetts (16), Maine (14), New Hampshire (4). Company revoked third-party access; 12 months Experian credit monitoring offered.

Root cause

Third-party CRM vulnerability exploitation

References