SHINDO3

Keio University

Unauthorized accessSize not disclosed

POSSIBLE LEAKPassword / Full nameContained

Open in the live monitor ▶
Disclosed
Dec 29, 2025
Detected
Nov 26, 2025
Detection to disclosure
33 days
Leak
Leak possible
Type
Unauthorized access
Status
Contained
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityUser name
ContactEmail address
Account dataStudent and staff ID numbers
CredentialsHashed login passwords, Email passwords (plain text), Encrypted Wi-Fi passwords

Who is affected

  • Students
  • Faculty and staff

Cause

Most likely a zero-day attack on a software vulnerability in a Cisco spam quarantine appliance, followed by lateral movement to the directory server

Timeline

  1. Unauthorized communications detected
  2. Zero-day exploitation identified
  3. Directory server breach discovered
  4. Security NEXT report date

Response

  • Password reset
  • Forensic investigation

Mass password reset, notified Cisco, investigation

What you should do

  1. Change this password and every account that reused it now. Weak passwords crack even when hashed or encrypted. Switch to a passkey where offered
  2. Don't open links in emails from this company. The apology email itself may be fake
  3. Expect targeted phishing posing as HR or interview contacts
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources