HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICLowContained
TOO LOST LLC
bd_2d71718d265351de · schema v1 · pii pii-v1
Full breach record for TOO LOST LLC →Too Lost LLC notified the California Attorney General of a data breach involving unauthorized access to a web application between July 25, 2025, and September 2, 2025. The company became aware of the incident in late January 2026 when contacted by an unauthorized third party. The breach involved names and basic contact information (address, email, phone). Passwords were not affected. The company engaged cybersecurity experts, contacted law enforcement, and confirmed data destruction. Credit monitoring is being offered to affected individuals.
California clockDiscovered Jan 31, 2026 → Notified Feb 20, 202620d ✓ CA 30-day OK20 days discovery → filing
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_0879145c47f3fbf5Vermont State AGfiled 2026-02-20Verified
- bd_32c22f4494912174Indiana State AGfiled 2026-02-20Verified by operator
- bd_373b6de6cb19f951New Hampshire State AGfiled 2026-02-20Verified
- bd_54386167de42a993Maine State AGfiled 2026-02-20Verified
Show 3 more filings ↓Show fewer ↑up to 34d gap
- bd_a10965c99e7afc61Indiana State AGfiled 2026-02-20Verified
- bd_8bce7e39abf24b6eTexas State AGfiled 2026-03-16(24d gap)Verified
- bd_979e794526725f7bNew Hampshire State AGfiled 2026-03-26(34d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-619060
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 20, 2026
- Raw hash
- b02862fae801604faa1c2bfabc2fb820756719a9075ebd54f0f95068de6eb8b1
Reporting entity
- Name
- TOO LOST LLCnorm: too lost
- Domain
- toolost.com
Victim entity
- Name
- TOO LOST LLCnorm: too lost
- Domain
- toolost.com
Incident
- Discovered
- Jan 31, 2026
- Materiality determined
- —
- Notification sent
- Feb 20, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 20 days(20 days from discovery to filing)
- Compliance flags
- CA 30-day OK · 20dCA AG copy ≤15d · 0d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jan 31, 2026→ Notified: Feb 20, 202620d 30 calendar days CA 30-day OK California Consumers notified: Feb 20, 2026→ AG copy submitted: Feb 20, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.