HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumActive
TOO LOST LLC
bd_373b6de6cb19f951 · schema v1 · pii pii-v1
Full breach record for TOO LOST LLC →Too Lost LLC notified the New Hampshire Attorney General of a data security incident involving unauthorized access to its web application between July 25, 2025, and September 2, 2025. The breach potentially exposed names, contact information, and for a limited number, government IDs (SSN, driver's license). Seven New Hampshire residents were identified as affected. Too Lost engaged forensic investigators, notified federal law enforcement, and is providing identity protection services.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_0879145c47f3fbf5Vermont State AGfiled 2026-02-20Verified
- bd_2d71718d265351deCalifornia State AGfiled 2026-02-20Candidate
- bd_32c22f4494912174Indiana State AGfiled 2026-02-20Verified by operator
- bd_54386167de42a993Maine State AGfiled 2026-02-20Verified
Show 3 more filings ↓Show fewer ↑up to 34d gap
- bd_a10965c99e7afc61Indiana State AGfiled 2026-02-20Verified
- bd_8bce7e39abf24b6eTexas State AGfiled 2026-03-16(24d gap)Verified
- bd_979e794526725f7bNew Hampshire State AGfiled 2026-03-26(34d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/too-lost-20260220.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 20, 2026
- Raw hash
- 8ce3b56f795cd383b46251652ad26e993f0dd333ca261144a060d3c49975ef6d
Reporting entity
- Name
- Paul Hastings LLPnorm: paul hastings
Victim entity
- Name
- TOO LOST LLCnorm: too lost
- Domain
- toolost.com
Incident
- Discovered
- Jan 31, 2026
- Materiality determined
- —
- Notification sent
- Feb 20, 2026
- Affected individuals
- 7
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General Consumer Protection & Antitrust Bureau
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 20 days(20 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.