GovPayNow.com, used by ~2,300 US government agencies for online payments, has exposed 14M+ customer records dating back to 2012, says issue has now been fixed
Government Payment Service Inc. — a company used by thousands of U.S. state and local governments to accept online payments …
Context & Ripple Effects
This breach lands mid-way through a 2018 run of failures in outsourced government data systems: hackers exploited a vulnerability in government payment software Click2Gov to steal card data across 46 cities, and the USPS patched an API flaw exposing details on 60 million users more than a year after disclosure. GovPayNow's exposure is the largest of the set — 14 million-plus records held by a vendor serving roughly 2,300 state and local agencies.
What makes it consequential is the timeline: records dating back to 2012 imply years of exposure at the exact layer where citizens hand payment data to government. Yet demand for these platforms kept growing — months after this story, PayIt raised a $100 million Series B to serve DMVs and other agencies, showing the market absorbed the security record rather than retreating from it.
First-order effects
- Customers who paid fines, utilities, or fees through any of the ~2,300 agencies on GovPayNow.com now have records spanning back to 2012 exposed, and Government Payment Service Inc. bears the notification and remediation burden while claiming the issue is fixed.
- The thousands of state and local agencies that delegated payments to the vendor must answer constituent questions about a breach they did not directly cause but are publicly attached to.
Second-order effects
- Competing platforms like PayIt gain a procurement argument built on this failure: agencies choosing a digital payments vendor now weigh vendor security posture as a selection criterion, not just price and coverage.
- Agencies that stayed on legacy in-house systems face pressure from both directions — outsourcing carries vendor-breach risk, but the Click2Gov and USPS incidents show self-run or long-patched systems fail too, forcing scrutiny of either path.
Third-order effects
- If the pattern holds — Click2Gov, the HealthCare.gov-adjacent system, USPS, and now GovPayNow — the structural lesson is that government digitization has outpaced the security maturity of its payment and data vendors, pushing procurement toward contractual security accountability and audit rights rather than trust in brand names.
- Repeated third-party breaches at the citizen-services layer create conditions for state-level or federal baseline security requirements for vendors handling government payment data, shifting compliance cost onto the platform layer.
The trend: Government services are digitizing through third-party payment platforms faster than those platforms are securing citizen data, making vendor security the deciding factor in public-sector procurement.