SHINDO6

MUFG Card

Personal data~400,000people

EXPOSEDCard number / Bank accountMisconfiguration · Contained

Open in the live monitor ▶
Disclosed
Feb 6, 2025
Detected
Dec 2024
Detection to disclosure
67 days
Leak
Exposed, access unknown
Type
Misconfiguration
Status
Contained
Security spend
Not checked yet
Compensation
Not announced

What leaked

Financial & paymentCredit card number, Expiry date, Bank account number
Account dataEnrollment date

How many

  • Affected customers (cumulative, including duplicates) ~400,000 people
  • Companies using the system, incl. the company, franchisees and contractors 16 organizations

Who is affected

  • Customers of MUFG Card franchisees

Cause

A misconfiguration made during a system update let each company's work terminals view credit card data of other franchisees' customers, instead of only their own

Timeline

  1. Detected
  2. Date of the Security NEXT report

Response

  • Config review

After discovery, fixed the system so the data cannot be viewed

What you should do

  1. Call your card issuer, reissue the card, check statements daily and turn on alerts
  2. Scammers who know your account number pose as refund staff. No bank or company asks for your PIN
  3. Check the company's notice to see if you're affected

Lessons for companies

  1. Two-person review and pre-release tests for sharing and cache changes; monitor cloud config (CSPM)
  2. Never sit on a known defect. Test every change before production
  3. Don't keep ID or bank data: delete after checks or use a KYC provider
  4. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  5. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources