SHINDO4

Nikke

RansomwareSize not disclosed

LEAK CONFIRMEDBank account / ID document (type not stated)Investigating

Open in the live monitor ▶
Disclosed
Sep 10, 2025
Detected
Aug 6, 2025
Detection to disclosure
35 days
Leak
Leak confirmed
Type
Ransomware
Status
Investigating
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name, Gender, Date of birth
ContactAddress, Phone number, Email address
Financial & paymentBank account information
Employment & HRHR records
ID documentsID documents
Special-care dataSensitive personal information

Who is affected

  • Employees
  • Former employees
  • Job applicants
  • Group business partners

Cause

A third party logged in with an administrator account and breached servers. Ransom notes were found on several servers, and stolen data was published on the dark web

Timeline

  1. Suspicious login with an administrator account detected
  2. Ransom notes found on several servers
  3. Publication of stolen data on the dark web confirmed
  4. Date of the Security NEXT report

Response

  • Password reset
  • Revoked credentials
  • Forensic investigation

What you should do

  1. ID numbers can never be changed. Request your credit file from CIC, JICC and others and look for contracts or loans you didn't make
  2. Register a self-declaration (honnin shinkoku) with the credit bureaus so lenders check applications in your name more carefully. The stronger loan self-restriction scheme also blocks your own borrowing and can't be withdrawn for 3 months. Neither stops bank accounts being opened
  3. Scammers who know your account number pose as refund staff. No bank or company asks for your PIN
  4. Health data can't be taken back. Don't answer blackmail; call the police (#9110) or the consumer hotline (188)
  5. Don't open links in emails from this company. The apology email itself may be fake
  6. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  7. Watch for unexpected mail or invoices; your address is hard to change
  8. Expect targeted phishing posing as HR or interview contacts
  9. Check the company's notice to see if you're affected

Lessons for companies

  1. Offline backups with restore drills; segment the network
  2. Don't keep ID or bank data: delete after checks or use a KYC provider
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources