SHINDO4

Digital Technology

Personal data~6,400people

LEAK CONFIRMEDPostal address / Date of birthUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Feb 27, 2025
Leak
Leak confirmed
Type
Unauthorized access
Status
Contained
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name, Date of birth (former employees)
ContactAddress, Phone number, Email address
Employment & HRHR information (former employees)

How many

  • Total of business contacts, former staff and recruitment contacts (approx. 4,600 + 500 + 1,300) ~6,400 people
  • Business contacts (business-card data) ~4,600 people
  • Former employees ~500 people
  • Recruitment-related people ~1,300 people

Who is affected

  • Business partners' staff
  • Former employees
  • Recruitment-related people (applicants)

Cause

The attacker made a VPN connection to a network device and got into the internal network

Timeline

  1. Early morning
  2. First disclosure
  3. Company issued an update

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Watch for unexpected mail or invoices; your address is hard to change
  4. Expect targeted phishing posing as HR or interview contacts
  5. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources