SHINDO3

Chugoku Electric

Personal data15,566people

POSSIBLE LEAKFull name / Email addressUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Apr 28, 2025
Detected
Apr 21, 2025
Detection to disclosure
7 days
Leak
Leak possible
Type
Unauthorized access
Status
Contained
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name
ContactWork email address
Account dataUser ID
CredentialsEncrypted passwords

How many

  • Employees, former employees, contractor staff and others 15,566 people

Who is affected

  • Employees of the company and group company Chugoku Electric Power Transmission & Distribution
  • Former employees
  • Contractor staff

Cause

Some of the devices used to connect to the internal network from outside, linked to a system holding employee personal data, had configuration flaws and were compromised

Timeline

  1. Detected
  2. Contained
  3. Individuals notified
  4. Reported to authority
  5. Date of the Security NEXT report

Response

  • Blocked the entry point
  • Password reset
  • Notified individuals

Disconnected the compromised device from the network the same day, informed the people concerned and asked them to change passwords. Reported to the Personal Information Protection Commission

What you should do

  1. Change this password and every account that reused it now. Weak passwords crack even when hashed or encrypted. Switch to a passkey where offered
  2. Don't open links in emails from this company. The apology email itself may be fake
  3. Expect targeted phishing posing as HR or interview contacts
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources