SHINDO3

Mitsubishi Auto Leasing Corporation

Personal data1,166records

LEAK CONFIRMEDFull name / PasswordUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Aug 15, 2025
Leak
Leak confirmed
Type
Unauthorized access
Status
Contained
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name
ContactBusiness email address
CredentialsHashed login passwords for company devices

Not leaked

  • Customer and business partner information

How many

  • Employees and contractor staff 1,166 records

Who is affected

  • Employees
  • Contractor staff

Cause

A third party exploited a vulnerability in the mobile device management server to gain access

Timeline

  1. Intrusion began
  2. Date of the Security NEXT report

Response

  • Patched
  • Forensic investigation
  • Notified individuals

What you should do

  1. Change this password and every account that reused it now. Weak passwords crack even when hashed or encrypted. Switch to a passkey where offered
  2. Don't open links in emails from this company. The apology email itself may be fake
  3. Expect targeted phishing posing as HR or interview contacts
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Inventory internal tools (BI, CMS) as exposed assets. 'Internal only' is not a defense
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources