SHINDO4

Nikkei

Personal data17,368people

POSSIBLE LEAKMessages / email bodies / Full nameInfostealer · Contained

Open in the live monitor ▶
Disclosed
Nov 4, 2025
Detected
Sep 2025
Detection to disclosure
64 days
Leak
Leak possible
Type
Infostealer
Status
Contained
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name
ContactEmail address
Communications & contentChat history

Not leaked

  • No leak of information on news sources or reporting has been confirmed

How many

  • Employees and business partners registered in Slack 17,368 people

Who is affected

  • Employees
  • Business partners

Cause

A personal computer owned by an employee was infected with malware; Slack credentials were stolen and used to log in to the employee's account

Timeline

  1. Damage identified in September 2025
  2. First disclosure

Response

  • Password reset
  • Notified individuals

Password changes and other measures; voluntary report to the PPC

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Expect targeted phishing posing as HR or interview contacts
  3. Check the company's notice to see if you're affected

Lessons for companies

  1. Passkeys or MFA for every account; monitor leaked credentials and rotate API keys
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources