SHINDO4

Mynavi

Personal data14,762records

EXPOSEDFull name / Employee numberMisconfiguration · Closed (final report)

Open in the live monitor ▶
Disclosed
Oct 17, 2025
Detected
Sep 2, 2025
Detection to disclosure
45 days
Leak
Exposed, access unknown
Type
Misconfiguration
Status
Closed (final report)
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name
Employment & HREmployee number, Job title, Department and work location
ContactCompany-assigned email address

How many

  • Employees and others issued company devices 14,762 records

Who is affected

  • Employees
  • Former employees
  • Temporary staff and contractors

Cause

An access permission error in a cloud system managing company-issued computers and mobile devices let third parties view employee personal data

Timeline

  1. Exposure began
  2. Detected
  3. Exposure ended
  4. Date of the Security NEXT report

Response

  • Access review
  • Config review

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Expect targeted phishing posing as HR or interview contacts
  3. Check the company's notice to see if you're affected

Lessons for companies

  1. Two-person review and pre-release tests for sharing and cache changes; monitor cloud config (CSPM)
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources