[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f9vj5r5rgmpex":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":32,"seoTitle":33,"seoTitleEn":34,"seoDescription":33,"seoDescriptionEn":35,"logoUrl":36,"isVerified":4,"isSensitive":4,"isSpamList":37,"isMalware":37,"company":38},"6a7199e7f4ca4a2499960b8f","TakedaPharmaceuticals2026","Takeda Pharmaceuticals 2026 Data Breach","takeda-pharmaceuticals-2026","takeda.com","2026-02-09T00:00:00.000Z","2026-08-04T07:51:02.450Z","2026-08-04T07:53:00.728Z","Massachusetts Attorney General consumer notification letter filed by Takeda Pharmaceuticals USA","https:\u002F\u002Fwww.mass.gov\u002Fdoc\u002F2026-880-takeda-pharmaceuticals-usa-inc\u002Fdownload",[15,17,18],"https:\u002F\u002Fmm.nh.gov\u002Ffiles\u002Fuploads\u002Fdoj\u002Fremote-docs\u002Ftakeda-pharmaceuticals-usa-20260529.pdf","https:\u002F\u002Foag.my.site.com\u002Fdatasecuritybreachreport\u002Fapex\u002FDataSecurityReportsPage",2435,"known",null,"people","Low",[25,26,27,28,29,30,31],"Names","Physical addresses","Dates of birth","Social security numbers","Driver's license numbers","Government issued IDs","Medical information","\u003Cp>\u003Cstrong>The Takeda Pharmaceuticals 2026 data breach\u003C\u002Fstrong> followed the compromise of a Takeda Pharmaceuticals USA employee account through voice phishing and the extraction of files from the company's environment. The unauthorised access lasted from 9 to 21 February 2026.\u003C\u002Fp>\u003Cp>Official regulatory records report that the incident affected 2,435 people in total. Takeda said the information available to it did not provide conclusive evidence that the data had been published or misused.\u003C\u002Fp>\u003Ch2>How was the incident confirmed?\u003C\u002Fh2>\u003Cp>Takeda's filing with the New Hampshire Attorney General confirms that an employee's credentials were compromised through a voice-phishing attack and that the unauthorised party extracted files from the company environment.\u003C\u002Fp>\u003Cp>A consumer letter filed with the Massachusetts Attorney General supports the core timeline and Takeda's response. The Texas Attorney General record provides the total affected-person count and the reported categories of personal information.\u003C\u002Fp>\u003Ch2>When did the breach occur?\u003C\u002Fh2>\u003Cp>The voice-phishing attack occurred on or around 9 February 2026. The unauthorised party accessed Takeda's environment and extracted certain files between 9 and 21 February.\u003C\u002Fp>\u003Cp>Takeda discovered the incident on 23 February 2026 and reset credentials and revoked sessions that day. The company determined on 24 April that personal information may have been accessed and identified affected individuals on 5 May.\u003C\u002Fp>\u003Ch2>What information may have been affected?\u003C\u002Fh2>\u003Cp>The reported data types include names, addresses, dates of birth, Social Security numbers, driver's license numbers, other government-issued identification numbers and medical information.\u003C\u002Fp>\u003Cp>Not every field necessarily applied to every person; notification letters identify the data relevant to each recipient. The company said it had found no conclusive evidence of misuse connected with the incident.\u003C\u002Fp>\u003Ch2>How many people were affected?\u003C\u002Fh2>\u003Cp>The filing with the Texas Attorney General reports a total of 2,435 affected individuals. This is the reported overall total, not only the number of Texas residents.\u003C\u002Fp>\u003Cp>State-specific counts were not added to that total again. For example, the New Hampshire filing identifies five residents and the Texas record identifies 392 residents of that state.\u003C\u002Fp>\u003Ch2>What risks do these data types create?\u003C\u002Fh2>\u003Cp>Social Security and government identification numbers can be used in attempts to open fraudulent accounts or bypass identity checks. Addresses and dates of birth can make those attempts appear more convincing.\u003C\u002Fp>\u003Cp>References to medical information can also be used in targeted messages disguised as healthcare or insurance notices. A message containing incident-specific details is not, by itself, proof that the sender is legitimate.\u003C\u002Fp>\u003Ch2>What should affected people do?\u003C\u002Fh2>\u003Cp>People who received a notice from Takeda should review credit reports, new-account enquiries and activity associated with their identity information. They can use the identity-monitoring service offered by the company and consider a credit freeze or fraud alert where appropriate.\u003C\u002Fp>\u003Cp>Instead of following links in messages claiming to be from Takeda or Experian, recipients should use the company's official website and the verified contact channels in their notification letter. Suspected identity misuse should be reported to the relevant institutions and official identity-theft reporting services.\u003C\u002Fp>","","Takeda Pharmaceuticals 2026 Data Breach (2.4 Thousand People Affected)","Review the verified Takeda Pharmaceuticals data breach timeline, the 2,435 people affected, the information involved and practical protective steps.","https:\u002F\u002Fassets-dam.takeda.com\u002Fimage\u002Fupload\u002Fv1683892920\u002FGlobal\u002FOG%20Logo.jpg",false,{"name":39,"sector":40,"country":41,"website":10,"websiteArchiveUrl":33,"websiteStatus":42,"websiteCheckedAt":12},"Takeda Pharmaceuticals USA, Inc.","Healthcare","United States","active"]