HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICLowContained
TOO LOST LLC
bd_979e794526725f7b · schema v1 · pii pii-v1
Full breach record for TOO LOST LLC →Too Lost LLC submitted a supplemental notification to the New Hampshire Attorney General regarding a data security incident. The breach involved unauthorized access to a web application between July 25, 2025, and September 2, 2025. The incident affected 19 New Hampshire residents, exposing names and basic contact information (address, email, phone). The company engaged cybersecurity experts and law enforcement, confirmed data destruction by the attacker, and offered credit monitoring services.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_8bce7e39abf24b6eTexas State AGfiled 2026-03-16(10d gap)Verified
- bd_0879145c47f3fbf5Vermont State AGfiled 2026-02-20(34d gap)Verified
- bd_2d71718d265351deCalifornia State AGfiled 2026-02-20(34d gap)Candidate
- bd_32c22f4494912174Indiana State AGfiled 2026-02-20(34d gap)Verified by operator
Show 3 more filings ↓Show fewer ↑up to 34d gap
- bd_373b6de6cb19f951New Hampshire State AGfiled 2026-02-20(34d gap)Verified
- bd_54386167de42a993Maine State AGfiled 2026-02-20(34d gap)Verified
- bd_a10965c99e7afc61Indiana State AGfiled 2026-02-20(34d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/too-lost-20260326.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 26, 2026
- Raw hash
- 1d37f9813ea55cf0b76724bd19aab0d8a952d131c8d380a2a83f6b88851645bf
Reporting entity
- Name
- TOO LOST LLCnorm: too lost
- Domain
- toolost.com
Victim entity
- Name
- TOO LOST LLCnorm: too lost
- Domain
- toolost.com
Incident
- Discovered
- Feb 10, 2026
- Materiality determined
- —
- Notification sent
- Feb 20, 2026
- Affected individuals
- 19
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- provided notice to the Office of the New Hampshire Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(44 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.