Complaint Against Too Lost LLC. Document Filed by Eric Martinez, Justin Graig. (Attachments: # 1 Exhibit 1 - Plaintiff Craig Data Breach Notice Letter).(Federman, William)
NATURE OF THE ACTION
1This class action arises out of Defendant’s failures to properly secure and safeguard Plaintiffs’ and Class Members’ sensitive personally identifiable information (“PII” or “Private Information”).
2“At the end of January 2026, Too Lost was contacted by an unauthorized third party” and following an investigation evidence indicated “unauthorized access and transfer of data involving” Too Lost LLC “between July 25, 2025, and September 2, 2025.”1
3Defendant’s data security failures allowed a targeted cyberattack to compromise Defendant’s network (the “Data Breach”) that, upon information and belief, contained the Private Information of Plaintiffs and other individuals (“the Class”). 1 Exhibit 1 (Plaintiffs’ Data Breach Notice Letters).
4Too Lost is a music and technology company, providing SaaS solutions for independent music rights holders. Our distribution and publishing services deliver, monetize and protect songs across the globe for over 400,000+ musicians, record labels, studios, brands, investors, and platforms. Too Lost is headquartered in New York, New York.2
5The Private Information compromised in the Data Breach included Plaintiffs’ and Class Members’ full names, contact information such as addresses, email addresses, and phone numbers. Upon information and belief, additional data such as payment information, account information, and more was compromised in the data breach.3
6The Data Breach was a direct result of Defendant’s failure to implement adequate and reasonable cyber-security procedures and protocols necessary to protect individuals’ Private Information with which it was entrusted.
7Upon information and belief, the mechanism of the Data Breach and potential for improper disclosure of Plaintiffs’ and Class Members’ Private Information was a known risk to Defendant, and thus Defendant was on notice that failing to take steps necessary to secure Private Information from those risks left that property in a dangerous condition.
8Upon information and belief, Defendant breached its duties and obligations by failing, in one or more of the following ways: (1) failing to design, implement, monitor, and maintain reasonable network safeguards against foreseeable threats; (2) failing to design, implement, and maintain reasonable data retention policies; (3) failing to adequately train staff on data security; (4) failing to comply with industry-standard data security practices; (5) failing to 2 https://toolost.com/about (last visited March 27, 2026). 3 https://ago.vermont.gov/document/2026-02-20-too-lost-data-breach-notice-consumer (citing “variable data” beyond the data confirmed to have been compromised); see also Exhibit 1 (Plaintiffs’ Data Breach Notice Letters). warn Plaintiffs and Class Members of Defendant’s inadequate data security practices; (6) failing to encrypt or adequately encrypt the Private Information; (7) failing to recognize or detect that its network had been compromised and accessed in a timely manner to mitigate the harm; (8) failing to utilize widely available software able to detect and prevent this type of attack; and (9) otherwise failing to secure the hardware using reasonable and effective data security procedures free of foreseeable vulnerabilities and data security incidents.
9Defendant impliedly understood its obligations and promised to safeguard Plaintiffs’ and Class Members’ Private Information. Plaintiffs and Class Members relied on these implied promises when seeking out and paying for education from Defendant. But for this mutual understanding, Plaintiffs and Class Members would not have provided Defendant with their Private Information. Defendant, however, did not meet these reasonable expectations, causing Plaintiffs and Class Members to suffer injury.
10Defendant disregarded the rights of Plaintiffs and Class Members (defined below) by, inter alia, intentionally, willfully, recklessly, and/or negligently failing to take adequate and reasonable measures to ensure its data systems were protected against unauthorized intrusions; failing to disclose that it did not have adequately robust computer systems and security practices to safeguard Plaintiffs’ and Class Members’ Private Information; failing to take standard and reasonably available steps to prevent the Data Breach; and failing to provide Plaintiffs and Class Members with prompt and full notice of the Data Breach.
11In addition, Defendant failed to properly monitor the computer network and systems that housed the Private Information. Had it properly monitored its property, it would have discovered the intrusion sooner rather than allowing cybercriminals a period of unimpeded access to the Private Information of Plaintiffs and Class Members.
12Plaintiffs’ and Class Members’ identities are now at risk because of Defendant’s negligent conduct since the Private Information that Defendant collected and maintained is now in the hands of data thieves.
13As a result of the Data Breach, Plaintiffs and Class Members are now at a current, imminent, and ongoing risk of fraud and identity theft. Plaintiffs and Class Members must now and for years into the future closely monitor their medical and financial accounts to guard against identity theft. As a result of Defendant’s unreasonable and inadequate data security practices, Plaintiffs and Class Members have suffered numerous actual and concrete injuries and damages.
14Plaintiffs and Class Members must now closely monitor their credit scores, financial accounts, and more to guard against future identity theft and fraud. Plaintiffs and Class Members have heeded such warnings to mitigate against the imminent risk of future identity theft and financial loss. Such mitigation efforts included and will continue to include in the future, among other things: (a) reviewing financial statements; (b) changing passwords; and (c) signing up for credit and identity theft monitoring services. The loss of time and other mitigation costs are tied directly to guarding against the imminent risk of identity theft.
15Plaintiffs and Class Members have suffered numerous actual and concrete injuries as a direct result of the Data Breach, including: (a) financial costs incurred mitigating the materialized risk and imminent threat of identity theft; (b) loss of time and loss of productivity incurred mitigating the materialized risk and imminent threat of identity theft; (c) financial costs incurred due to actual identity theft; (d) loss of time incurred due to actual identity theft; (g) deprivation of value of their Private Information; and (h) the continued risk to their sensitive Private Information, which remains in the possession of Defendant, and which is subject to further breaches, so long as Defendant fails to undertake appropriate and adequate measures to protect it collected and maintained.
16Through this Complaint, Plaintiffs seek to remedy these harms on behalf of all similarly situated individuals whose Private Information was compromised and/or stolen during the Data Breach.
17Accordingly, Plaintiffs brings this action against Defendant seeking redress for its unlawful conduct and asserting claims for: (i) negligence and negligence per se, (ii) breach of implied contract, (iii) unjust enrichment, and (iv) declaratory relief.
18Plaintiffs seek remedies including, but not limited to, compensatory damages, reimbursement of out-of-pocket costs, and injunctive relief including improvements to Defendant’s data security systems, future annual audits, as well as long-term and adequate credit monitoring services funded by Defendant, and declaratory relief.
19The exposure of one’s Private Information to cybercriminals is a bell that cannot be un-rung. Before this Data Breach, Plaintiffs’ and the Class’s Private Information was exactly that—private. Not anymore. Now, their Private Information is forever exposed and unsecure.
PARTIES
20Plaintiff Justin Craig is an adult individual who at all relevant times has been a citizen and resident of Palatine, Illinois.
21Plaintiff Eric Martinez is an adult individual who at all relevant times has been a citizen and resident of Round Lake Beach, Illinois.
22Defendant Too Lost LLC is a for-profit enterprise with its headquarters and principal place of business located in New York, New York. Defendant “is a music and technology company, providing SaaS solutions for independent music rights holders.”4 4 https://toolost.com/about/
Read the full filing
You’re reading pages 1–5 of 39. Register free to read the complete 39-page transcript on this page.
Register free to continue reading →
These are public U.S. federal court records, available free from PACER and the court. Registration unlocks our full on-page transcript — a convenience service.
advertisement
Public U.S. federal court record (district court docket 73106622, document 1). Source via the RECAP Archive (Free Law Project). The same record is available from PACER. Informational only — not legal advice.