SHINDO3

Kansai Airports

Member records10,575records

LEAK CONFIRMEDPostal address / Phone numberUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Apr 30, 2025
Detected
Apr 24, 2025
Detection to disclosure
6 days
Leak
Leak confirmed
Type
Unauthorized access
Status
Contained
Security spend
Not checked yet
Compensation
Not announced

What leaked

Business dataMember company name
ContactAddress, Phone number, Email address
Employment & HRContact person's job title, Contact person's department

How many

  • Member records 10,575 records
  • Member company records (incl. email addresses) 815 records
  • Email addresses of individual users 9,760 records

Who is affected

  • Member companies
  • Individual user members

Cause

The server managing the membership service was repeatedly accessed from outside. During a vulnerability assessment, the company found some information could be viewed by third parties

Timeline

  1. Intrusion began
  2. Detected
  3. Date of the Security NEXT report

Response

  • Vulnerability testing

Will strengthen security measures to prevent recurrence

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Watch for unexpected mail or invoices; your address is hard to change
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources