Clustered 4 filings across 4 jurisdictions · filing window Feb 25, 2026 → Feb 27, 2026. View entity profile → Other incidents for this victim →
incident inc_9030f2e6d66b4c46 · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
PII
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
CA IN NH TX
all State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
Aug 23, 2025
When the intrusion reportedly occurred, per the linked filings
Oct 31, 2025
Reported by NEW HAMPSHIRE AG, CALIFORNIA AG filings
Feb 20, 2026
Reported by TEXAS AG filing
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Flash Charm Inc. (dba Idera) notified the NH Attorney General of a breach involving its Egnyte file hosting platform. Unauthorized access occurred on October 31, 2025, affecting 7 NH residents. Data exposed included names, contact info, SSNs, bank account numbers, and health insurance info. Contained Nov 8, 2025. Notifications sent Feb 26, 2026, offering 2 years credit monitoring.
Affected (this filing): 7
Idera (Flash Charm, Inc.) detected unauthorized access to a third-party file-hosting system on October 31, 2025. The breach occurred on August 23, 2025. Affected data includes names and basic contact information. Idera contained the incident, notified law enforcement, and is offering two years of credit monitoring to affected individuals.
Flash Charm Inc dba Idera reported a data breach to the Indiana Attorney General. The breach occurred on 2025-08-23 and was reported on 2026-02-26. 3 Indiana residents were affected. 2,015 individuals affected in total.
Affected (this filing): 2,015
Flash Charm, Inc. d/b/a Idera based in Austin, Texas, a business – retail or merchant entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-02-20 and reported on 2026-02-27. 606 Texas residents were affected. 2,015 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Driver’s License number;Government-issued ID number (e.g. passport, state ID card);Financial Information (e.g. account number, credit or debit card number);Health Insurance Information;Date of Birth. Consumers were notified via U.S. Mail.
Affected (this filing): 606