SHINDO3

Chuo University

Personal dataup to1,082people

POSSIBLE LEAKFull name / Email addressAccount takeover · Closed (final report)

Open in the live monitor ▶
Disclosed
Sep 25, 2025
Leak
Leak possible
Type
Account takeover
Status
Closed (final report)
Security spend
Not checked yet
Compensation
Not announced

What leaked

ContactEmail address
IdentityDisplay name such as full name
Communications & contentMail index information

How many

  • People who exchanged email with the accounts up to July 23, 2025 up to 1,082 people

Who is affected

  • Email correspondents

Cause

Two faculty members' email accounts on the university mail server were accessed without authorization, and mail index information may have been viewed by a third party

Timeline

  1. Correspondents up to this date affected
  2. Date of the Security NEXT report

Response

  • Notified individuals
  • Phishing warning

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. You can be affected without ever using this service (parcel recipients etc.). Check any notice you receive
  3. Check the company's notice to see if you're affected

Lessons for companies

  1. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  2. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources