HackingVulnerability ExploitCapture Stored DataData ExfiltratedTargetedIDENTITY_BASICLowContained
TOO LOST LLC
bd_0879145c47f3fbf5 · schema v1 · pii pii-v1
Full breach record for TOO LOST LLC →Too Lost notified consumers of a data breach involving unauthorized access to its web application between July 25, 2025, and September 2, 2025. The incident compromised basic contact information (name, address, email, phone). Too Lost engaged cybersecurity experts and law enforcement, confirmed data destruction by the attacker, and offered credit monitoring services.
Vermont clock✓ VT AG ≤14 bday20 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_2d71718d265351deCalifornia State AGfiled 2026-02-20Candidate
- bd_32c22f4494912174Indiana State AGfiled 2026-02-20Verified by operator
- bd_373b6de6cb19f951New Hampshire State AGfiled 2026-02-20Verified
- bd_54386167de42a993Maine State AGfiled 2026-02-20Verified
Show 3 more filings ↓Show fewer ↑up to 34d gap
- bd_a10965c99e7afc61Indiana State AGfiled 2026-02-20Verified
- bd_8bce7e39abf24b6eTexas State AGfiled 2026-03-16(24d gap)Verified
- bd_979e794526725f7bNew Hampshire State AGfiled 2026-03-26(34d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2026-02-20-too-lost-data-breach-notice-consumer
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 20, 2026
- Raw hash
- 51f48fa589c1a92915a61a4ad199ac447fe4176c84a2ce024cbf2d40ef14b041
Reporting entity
- Name
- TOO LOST LLCnorm: too lost
- Domain
- toolost.com
Victim entity
- Name
- TOO LOST LLCnorm: too lost
- Domain
- toolost.com
Incident
- Discovered
- Jan 31, 2026
- Materiality determined
- Feb 10, 2026
- Notification sent
- Feb 20, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- contacted law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 20 days(20 days from discovery to filing)
- Compliance flags
- VT AG ≤14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.