DisclosureLens
HackingRetail & ConsumerRetailCustomer Data InvolvedIdentity (basic)Government IDMediumContained

Retail Therapy LLC

bd_a759ec217efecd1c · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

Apr 14, 2026

To disclose

Affected

1state residents only

Linked

4 filings

Confidence

66%
Full breach record for Retail Therapy LLC

Retail Therapy LLC, a retail entity, notified Nebraska regulators of a cybersecurity incident where an unauthorized third party accessed systems between Nov 20 and Dec 11, 2025. The breach potentially exposed PII including SSNs, driver's licenses, and passport numbers. One Nebraska resident was notified on April 14, 2026. The company engaged federal law enforcement, provided 12 months of credit monitoring via TransUnion, and implemented additional employee safeguards.

Incident timeline

Nov 20, 2025

Begins

Apr 14, 2026

Filed

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 4 states

View merged incident ↗
Massachusetts State AGApr 14 · first
New Hampshire State AGApr 14 · first
Maine State AGApr 14 · first
Nebraska State AGApr 14 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.