SHINDO3

Nishitetsu

Personal data3,019records

POSSIBLE LEAKPostal address / Phone numberUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
May 15, 2025
Detected
May 7, 2025
Detection to disclosure
8 days
Leak
Leak possible
Type
Unauthorized access
Status
Contained
Security spend
Not checked yet
Compensation
Not announced

What leaked

Business dataCompany name, Contact person name
ContactAddress, Phone number, Email address
Employment & HRDepartment
IdentityRepresentative's name

How many

  • Registered customer (company) records 3,019 records

Who is affected

  • Companies registered for the eco corporate commuter pass

Cause

The site was breached through a development program used when the site was built and left on the server afterwards

Timeline

  1. Intrusion began
  2. Found after registered companies reported they could not log in
  3. Blocked outside access and deleted the development program
  4. Date of the Security NEXT report

Response

  • Blocked the entry point
  • Data deleted
  • Notified individuals
  • Service stopped

Blocked outside access to the site and deleted the development program. Notifying affected customers individually. The site stays offline until a full security overhaul

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Watch for unexpected mail or invoices; your address is hard to change
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Never sit on a known defect. Test every change before production
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources