Clustered 3 filings across 3 jurisdictions · filing window May 1, 2026 → Jun 26, 2026. View entity profile → Other incidents for this victim →
incident inc_30ec41cf9de846e0 · merge_method deterministic · confidence 95%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Identity (basic)
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
MA NH TX
all State AG
Earliest sighting first · deep chronology in Litigation Timeline
Feb 9, 2026 → Feb 21, 2026
When the intrusion reportedly occurred, per the linked filings
Feb 23, 2026
Reported by MASSACHUSETTS AG, NEW HAMPSHIRE AG, TEXAS AG filings
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Takeda Pharmaceuticals USA, Inc. notified Massachusetts residents of a security incident discovered on February 23, 2026, where an unauthorized third party compromised an employee's credentials. The incident involved access to personal information including names. Takeda contained the incident, notified law enforcement, and offered 24 months of Experian IdentityWorks services.
Takeda Pharmaceuticals USA, Inc. notified the New Hampshire Attorney General of a security incident where an unauthorized third party compromised employee credentials via voice phishing (vishing) around February 9, 2026. The actor exfiltrated files containing personal information (name, SSN, DOB, driver's license) of 5 New Hampshire residents between February 9 and 21, 2026. Takeda discovered the breach on February 23, 2026, contained it, and began notifying affected individuals on May 29, 2026, offering 24 months of credit monitoring.
Affected (this filing): 5
Takeda Pharmaceuticals USA, Inc. based in Cambridge, Massachusetts, a other entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-02-23 and reported on 2026-06-26. 392 Texas residents were affected. 2,435 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Driver’s License number;Government-issued ID number (e.g. passport, state ID card);Medical Information;Date of Birth. Consumers were notified via U.S. Mail.
Affected (this filing): 392