SHINDO4

Kensoh

Unauthorized accessSize not disclosed

LEAK CONFIRMEDPostal address / Date of birthContained

Open in the live monitor ▶
Disclosed
Apr 15, 2025
Detected
Jan 28, 2025
Detection to disclosure
77 days
Leak
Leak confirmed
Type
Unauthorized access
Status
Contained
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name, Date of birth (employees)
ContactPhone number (business partners), Email address (business partners), Address
Business dataCompany name
Employment & HRHR information
Financial & paymentNumber of shares held

Who is affected

  • Some business partners
  • Some company employees
  • Former employees
  • Shareholders as of the end of March and end of September 2020

Cause

Unauthorized access exploiting a server vulnerability

Timeline

  1. Detected
  2. Date of the Security NEXT report (earliest disclosure seen)

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Watch for unexpected mail or invoices; your address is hard to change
  4. Expect targeted phishing posing as HR or interview contacts
  5. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Don't keep ID or bank data: delete after checks or use a KYC provider
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources