SHINDO2

GovTech Tokyo

Course participants561people

EXPOSEDFull name / Email addressMisconfiguration · Closed (final report)

Open in the live monitor ▶
Disclosed
Aug 8, 2025
Detected
Aug 5, 2025
Detection to disclosure
3 days
Leak
Exposed, access unknown
Type
Misconfiguration
Status
Closed (final report)
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name
ContactEmail address

How many

  • Course participants 561 people

Who is affected

  • Course participants

Cause

The contractor misconfigured viewing permissions in the course progress management tool, so participants could see other participants' personal data

Timeline

  1. Exposure began
  2. Reported by a participant in the evening
  3. Contractor informed GovTech Tokyo
  4. Permissions corrected
  5. First disclosure

Response

  • Access review
  • Notified individuals
  • Staff training
  • Change process

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Check the company's notice to see if you're affected

Lessons for companies

  1. Put security requirements, audit rights and reporting deadlines in vendor contracts
  2. Two-person review and pre-release tests for sharing and cache changes; monitor cloud config (CSPM)
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources