SHINDO4

Nippo Valve

Employees343people

LEAK CONFIRMEDHealth / medical / treatment / Postal addressRansomware · Recovering

Open in the live monitor ▶
Disclosed
Mar 31, 2025
Detected
Mar 18, 2025
Detection to disclosure
13 days
Leak
Leak confirmed
Type
Ransomware
Status
Recovering
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name, Date of birth, Gender
ContactAddress, Phone number, Email address
Special-care dataHealth checkup results
Business dataSales summaries, meeting materials, internal review documents and other data

How many

  • Employees 343 people

Who is affected

  • Company employees

Cause

Ransomware encrypted server data. Firewall vulnerabilities and outdated anti-malware software allowed the breach

Timeline

  1. Detected
  2. Date of the first Security NEXT report
  3. Reported to authority
  4. Company issued an update

What you should do

  1. Health data can't be taken back. Don't answer blackmail; call the police (#9110) or the consumer hotline (188)
  2. Don't open links in emails from this company. The apology email itself may be fake
  3. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  4. Watch for unexpected mail or invoices; your address is hard to change
  5. Expect targeted phishing posing as HR or interview contacts
  6. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Offline backups with restore drills; segment the network
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources