SHINDO3

ASKUL / LOHACO

RansomwareSize not disclosed

LEAK CONFIRMEDPostal address / Phone numberRecovering

Open in the live monitor ▶
Disclosed
Oct 19, 2025
Leak
Leak confirmed
Type
Ransomware
Status
Recovering
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name
ContactDelivery address, Phone number
Transactions & activityOrdered product information, Customer inquiry information

Not leaked

  • Credit card information is not held, so it was not leaked

Who is affected

  • Customers (people who made inquiries)
  • Suppliers
  • Customers of logistics clients (delivery recipients)

Cause

System outage caused by a ransomware infection

Timeline

  1. Orders and shipping halted for ASKUL, Soloel Arena and LOHACO; already accepted orders cancelled
  2. First disclosure
  3. RansomHouse claimed the attack
  4. Leak of customer inquiry information and more announced
  5. Second data release claimed
  6. Possible leak of ASKUL LOGIST contract logistics data

Response

  • Forensic investigation
  • More monitoring
  • Service stopped
  • Phishing warning

Forensic investigation by an outside specialist organization, stronger monitoring, warnings about possible misuse of information

What you should do

  1. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  2. Watch for unexpected mail or invoices; your address is hard to change
  3. You can be affected without ever using this service (parcel recipients etc.). Check any notice you receive
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Offline backups with restore drills; segment the network
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources