SHINDO6
MUFG Card
Mitsubishi UFJ NICOS Co., Ltd.
Personal data~400,000people
EXPOSEDCard number / Bank accountMisconfiguration · Contained
Open in the live monitor ▶- Disclosed
- Feb 6, 2025
- Detected
- Dec 2024
- Detection to disclosure
- 67 days
- Leak
- Exposed, access unknown
- Type
- Misconfiguration
- Status
- Contained
- Security spend
- Not checked yet
- Compensation
- Not announced
What leaked
Financial & paymentCredit card number, Expiry date, Bank account number
Account dataEnrollment date
How many
- Affected customers (cumulative, including duplicates) ~400,000 people
- Companies using the system, incl. the company, franchisees and contractors 16 organizations
Who is affected
- Customers of MUFG Card franchisees
Cause
A misconfiguration made during a system update let each company's work terminals view credit card data of other franchisees' customers, instead of only their own
Timeline
- Detected
- Date of the Security NEXT report
Response
- Config review
After discovery, fixed the system so the data cannot be viewed
What you should do
- Call your card issuer, reissue the card, check statements daily and turn on alerts
- Scammers who know your account number pose as refund staff. No bank or company asks for your PIN
- Check the company's notice to see if you're affected
Lessons for companies
- Two-person review and pre-release tests for sharing and cache changes; monitor cloud config (CSPM)
- Never sit on a known defect. Test every change before production
- Don't keep ID or bank data: delete after checks or use a KYC provider
- Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
- Run red teaming and AI-assisted hardening, and publish how much you invest
Sources
- Security NEXT News · Feb 6, 2025