SHINDO2

Jimoty

Malware infectionSize not disclosed

LEAK CONFIRMEDFull name / Email addressContained

Open in the live monitor ▶
Disclosed
Dec 8, 2025
Detected
Nov 26, 2025
Detection to disclosure
12 days
Leak
Leak confirmed
Type
Malware infection
Status
Contained
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name
ContactEmail address
Transactions & activityInformation indicating whether there were inquiries in a specific category

Who is affected

  • Employees
  • Former employees
  • Outside development contractors
  • Users (inquiry history)

Cause

The development environment was breached and infected with malware; an environment holding personal data was accessible from outside, and some data was actually accessed

Timeline

  1. Access blocked immediately after detection
  2. Contained
  3. Detected
  4. First disclosure

Response

  • Blocked the entry point
  • Forensic investigation

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Expect targeted phishing posing as HR or interview contacts
  3. Check the company's notice to see if you're affected

Lessons for companies

  1. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  2. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources