SHINDO3

Gibraltar Life

Personal data550records

LEAK CONFIRMEDFull name / Email addressUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Jun 25, 2025
Detected
May 22, 2025
Detection to disclosure
34 days
Leak
Leak confirmed
Type
Unauthorized access
Status
Contained
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name
Account dataUser ID
ContactWork email address

How many

  • Employees, former employees and contractor staff on record from 2015 to 2023 550 records

Who is affected

  • Employees
  • Former employees
  • Contractor staff

Cause

The mobile device management (MDM) server was compromised through a vulnerability. Because of the product's design, deleted data remained on the server and was leaked

Timeline

  1. Intrusion began
  2. Detected
  3. Date of the Security NEXT report

Response

  • Blocked the entry point
  • Patched
  • Notified individuals

Cut the affected server off from the internet and fixed the vulnerability. Reported to the relevant authorities and notified affected staff individually

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Expect targeted phishing posing as HR or interview contacts
  3. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Inventory internal tools (BI, CMS) as exposed assets. 'Internal only' is not a defense
  3. Data outlived the contract. Always get proof of deletion and set retention limits
  4. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  5. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources