SHINDO3

Habatan Pay+

Personal dataup to34people

LEAK CONFIRMEDMy Number images / Health insurance card imagesSoftware defect · Closed (final report)

Open in the live monitor ▶
Disclosed
Oct 24, 2025
Leak
Leak confirmed
Type
Software defect
Status
Closed (final report)
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name, Date of birth, Gender
ContactAddress, Phone number, Email address
ID documentsMy Number card image (specified personal information) (image), Child medical expense certificate image (image)
Special-care dataMaternal and child health handbook image (image)

How many

  • Applicants whose data may have been displayed up to 34 people
  • Invalid applications that displayed another applicant's data 17 records

Who is affected

  • Child-rearing support category applicants

Cause

Because of a fault in integration between several servers, a button on the completion screen shown after an invalid application linked to another person's page

Timeline

  1. Applications opened
  2. First disclosure

What you should do

  1. ID numbers can never be changed. Request your credit file from CIC, JICC and others and look for contracts or loans you didn't make
  2. Register a self-declaration (honnin shinkoku) with the credit bureaus so lenders check applications in your name more carefully. The stronger loan self-restriction scheme also blocks your own borrowing and can't be withdrawn for 3 months. Neither stops bank accounts being opened
  3. Health data can't be taken back. Don't answer blackmail; call the police (#9110) or the consumer hotline (188)
  4. Don't open links in emails from this company. The apology email itself may be fake
  5. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  6. Watch for unexpected mail or invoices; your address is hard to change
  7. Check the company's notice to see if you're affected

Lessons for companies

  1. Don't keep ID or bank data: delete after checks or use a KYC provider
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources