DisclosureLens
HackingPIIIdentity (basic)Government IDEmploymentFinancial accountMediumContained

MAX USA Corp.

bd_cdd2d0c79f44fe3b · schema v1 · pii pii-v2

Severity

Medium

Discovered

Jan 13, 2026

Filed

Jan 15, 2026

To disclose

Affected

Not disclosed

Linked

5 filings

Confidence

65%
Full breach record for MAX USA Corp.

MAX USA CORP. reported a security incident discovered on January 13, 2026, involving unauthorized access to network files between January 11-13, 2026. The breach exposed business and employment records, including names, SSNs, driver's license numbers, and payroll/benefits data. MAX USA isolated systems, reset credentials, and engaged forensic specialists. Affected individuals were offered 24 months of IDX identity protection services. No evidence of data misuse was found at the time of notification.

Incident timeline

undetected · 2 days

Jan 11, 2026

Begins

Jan 13, 2026

Discovered

Jan 15, 2026

Filed

This filing is one of 5 about the same incident.View merged incident

Linked disclosures

Why this link?

Ransomware claims (2)

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
Nebraska State AGJan 15 · first · this page

Pattern: first filing Jan 15 (NE), last Feb 20 (NH) — a 36-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.