MAX USA Corp.
bd_cdd2d0c79f44fe3b · schema v1 · pii pii-v2
Full breach record for MAX USA Corp. →MAX USA CORP. reported a security incident discovered on January 13, 2026, involving unauthorized access to network files between January 11-13, 2026. The breach exposed business and employment records, including names, SSNs, driver's license numbers, and payroll/benefits data. MAX USA isolated systems, reset credentials, and engaged forensic specialists. Affected individuals were offered 24 months of IDX identity protection services. No evidence of data misuse was found at the time of notification.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 11, 2026
Begins
Jan 13, 2026
Discovered
Jan 15, 2026
Filed
Linked disclosures
Why this link?Ransomware claims (2)
- Leak Sitelockbit5bd_b670437a600ae18f2026-02-15 · +32dVerified by operator
- Leak Sitelockbit5bd_e7cf7b6edda22c762026-01-26 · +11dVerified by operator
Regulatory filings (2) · sorted by filing gap
- Massachusetts State AGbd_d7f76c6a659b0c5b2026-02-18 · +34dVerified
- New Hampshire State AGbd_751bb5530112b2992026-02-20 · +36dCandidate
Filing propagation · 3 filings · 3 states
View merged incident ↗Pattern: first filing Jan 15 (NE), last Feb 20 (NH) — a 36-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.