Clustered 8 filings across 6 jurisdictions · filing window Feb 20, 2026 → Mar 26, 2026. View entity profile → Other incidents for this victim →
incident inc_04f4707fb61c45ae · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
PII
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
CA IN ME NH TX VT
all State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
8 filings across 6 jurisdictions · Feb 20, 2026 – Mar 26, 2026 · 3 milestones
Jul 25, 2025
When the intrusion reportedly occurred, per the linked filings
Jan 31, 2026
Reported by CALIFORNIA AG, NEW HAMPSHIRE AG, VERMONT AG filings
Feb 10, 2026
Reported by MAINE AG, TEXAS AG, NEW HAMPSHIRE AG filings
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Too Lost notified consumers of a data breach involving unauthorized access to its web application between July 25, 2025, and September 2, 2025. The incident compromised basic contact information (name, address, email, phone). Too Lost engaged cybersecurity experts and law enforcement, confirmed data destruction by the attacker, and offered credit monitoring services.
Too Lost LLC notified the California Attorney General of a data breach involving unauthorized access to a web application between July 25, 2025, and September 2, 2025. The company became aware of the incident in late January 2026 when contacted by an unauthorized third party. The breach involved names and basic contact information (address, email, phone). Passwords were not affected. The company engaged cybersecurity experts, contacted law enforcement, and confirmed data destruction. Credit monitoring is being offered to affected individuals.
Too Lost LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2025-07-25 and was reported on 2026-02-20. 85 Indiana residents were affected. 3,206 individuals affected in total.
Affected (this filing): 3,206
Too Lost LLC notified the New Hampshire Attorney General of a data security incident involving unauthorized access to its web application between July 25, 2025, and September 2, 2025. The breach potentially exposed names, contact information, and for a limited number, government IDs (SSN, driver's license). Seven New Hampshire residents were identified as affected. Too Lost engaged forensic investigators, notified federal law enforcement, and is providing identity protection services.
Affected (this filing): 7
Too Lost LLC, a New York-based company, notified Maine residents of a data security incident in which an unauthorized third party accessed and exfiltrated data from a Too Lost web application between July 25, 2025 and September 2, 2025. The actor contacted Too Lost at end of January 2026 claiming to have obtained data. Affected information included names and basic contact details (address, email, phone). 2 Maine residents affected out of 3,206 total. IDX credit monitoring offered for 12 months.
Affected (this filing): 2
Too Lost LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2025-07-25 and was reported on 2026-02-20. 85 Indiana residents were affected. 3,206 individuals affected in total.
Affected (this filing): 3,206
Too Lost LLC based in New York, New York, a other entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-02-10 and reported on 2026-03-16. 523 Texas residents were affected. 27,695 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Driver’s License number;Government-issued ID number (e.g. passport, state ID card);Date of Birth. Consumers were notified via U.S. Mail;Email.
Affected (this filing): 523
Too Lost LLC submitted a supplemental notification to the New Hampshire Attorney General regarding a data security incident. The breach involved unauthorized access to a web application between July 25, 2025, and September 2, 2025. The incident affected 19 New Hampshire residents, exposing names and basic contact information (address, email, phone). The company engaged cybersecurity experts and law enforcement, confirmed data destruction by the attacker, and offered credit monitoring services.
Affected (this filing): 19