SHINDO3

AG Payment Service

Credit applicants719records

LEAK CONFIRMEDFull name / Merchant dataSoftware defect · Closed (final report)

Open in the live monitor ▶
Disclosed
May 28, 2025
Leak
Leak confirmed
Type
Software defect
Status
Closed (final report)
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name
Business dataName of the merchant applied through
Financial & paymentApplication amount

How many

  • Credit applicants 719 records

Who is affected

  • Credit applicants

Cause

A defect introduced during a system update let certain merchants other than the one applied through view applicants' data

Timeline

  1. Exposure began
  2. Exposure ended
  3. Date of the Security NEXT report

Response

  • Data deleted
  • Change process

Asked the merchants to delete the data and received reports that it was deleted. The system was fixed and works normally

What you should do

  1. Check the company's notice to see if you're affected

Lessons for companies

  1. Never sit on a known defect. Test every change before production
  2. Don't keep ID or bank data: delete after checks or use a KYC provider
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources