TENGA USA INC reported that on February 13, 2026, an unauthorized party gained access to an employee's professional email account. The attacker used the account to send unsolicited spam emails to contacts. Affected data included names, email addresses, and historical email correspondence. No SSNs or billing information were involved. The company reset credentials, enabled MFA, and notified law enforcement.