SHINDO5

AXA Direct

Personal data~543,000records

POSSIBLE LEAKBank account / Date of birthUnauthorized access · Closed (final report)

Open in the live monitor ▶
Disclosed
Jul 2025
Detected
Jul 2025
Detection to disclosure
Same day
Leak
Leak possible
Type
Unauthorized access
Status
Closed (final report)
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name, Date of birth
ContactAddress, Phone number, Email address
Transactions & activityPolicy number, Claim history and payout information
Financial & paymentBank account information

How many

  • Total (sum of three categories) ~543,000 records
  • Existing policyholders and insured ~143,000 records
  • Quote and brochure requests ~399,000 records
  • Liability insurance claimants ~1,000 records

Who is affected

  • Policyholders and insured
  • People who requested quotes or brochures
  • Parties to liability insurance claims

Cause

A cyberattack on the pet insurance system involved unauthorized access and data theft between March 19 and April 21, 2025

Timeline

  1. Intrusion began
  2. Intrusion stopped
  3. Suspicious server activity detected
  4. First disclosure
  5. Forensic investigation completed October 24; results announced

Response

  • Forensic investigation
  • Notified individuals

What you should do

  1. Scammers who know your account number pose as refund staff. No bank or company asks for your PIN
  2. Don't open links in emails from this company. The apology email itself may be fake
  3. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  4. Watch for unexpected mail or invoices; your address is hard to change
  5. You can be affected without ever using this service (parcel recipients etc.). Check any notice you receive
  6. Check the company's notice to see if you're affected

Lessons for companies

  1. Never sit on a known defect. Test every change before production
  2. Don't keep ID or bank data: delete after checks or use a KYC provider
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources