HackingVulnerability ExploitCapture App DataData ExfiltratedCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_BASICLowContained
TOO LOST LLC
bd_54386167de42a993 · schema v1 · pii pii-v1
Full breach record for TOO LOST LLC →Too Lost LLC, a New York-based company, notified Maine residents of a data security incident in which an unauthorized third party accessed and exfiltrated data from a Too Lost web application between July 25, 2025 and September 2, 2025. The actor contacted Too Lost at end of January 2026 claiming to have obtained data. Affected information included names and basic contact details (address, email, phone). 2 Maine residents affected out of 3,206 total. IDX credit monitoring offered for 12 months.
Maine clockDiscovered Feb 10, 2026 → Filed with AG Feb 20, 202610d ✓ ME AG ≤30d10 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_0879145c47f3fbf5Vermont State AGfiled 2026-02-20Verified
- bd_2d71718d265351deCalifornia State AGfiled 2026-02-20Candidate
- bd_32c22f4494912174Indiana State AGfiled 2026-02-20Verified by operator
- bd_373b6de6cb19f951New Hampshire State AGfiled 2026-02-20Verified
Show 3 more filings ↓Show fewer ↑up to 34d gap
- bd_a10965c99e7afc61Indiana State AGfiled 2026-02-20Verified
- bd_8bce7e39abf24b6eTexas State AGfiled 2026-03-16(24d gap)Verified
- bd_979e794526725f7bNew Hampshire State AGfiled 2026-03-26(34d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/c38e9a02-17f5-40b8-993a-48b55bc01c5f.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 20, 2026
- Raw hash
- b943d1611b2adb8590ea229c808e979a86346bac147ba8c1568a279e87b620d3
Reporting entity
- Name
- TOO LOST LLCnorm: too lost
- Domain
- toolost.com
- Industry
- Other Commercial
Victim entity
- Name
- TOO LOST LLCnorm: too lost
- Domain
- toolost.com
- Industry
- Other Commercial
Incident
- Discovered
- Feb 10, 2026
- Materiality determined
- —
- Notification sent
- Feb 20, 2026
- Affected individuals
- 2
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Maine Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 10 days(10 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 10d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Feb 10, 2026→ Filed with AG: Feb 20, 202610d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.