SHINDO5

NSSOL

Personal data~90,000records

POSSIBLE LEAKPostal address / Phone numberUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Jul 10, 2025
Detected
Mar 7, 2025
Detection to disclosure
125 days
Leak
Leak possible
Type
Unauthorized access
Status
Contained
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name
Business dataCompany name
Employment & HRDepartment, Job title
ContactAddress, Business email address, Phone number

How many

  • Customer, business partner and employee records ~90,000 records

Who is affected

  • Customers (client company staff)
  • Business partners
  • Employees

Cause

A zero-day vulnerability in network equipment was exploited to access servers. The software was up to date, but no patch existed at the time of the attack

Timeline

  1. Suspicious access to servers detected; servers isolated from the network
  2. Client Hosei University informed
  3. Date of the Security NEXT report

Response

  • Blocked the entry point
  • Forensic investigation

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Watch for unexpected mail or invoices; your address is hard to change
  4. Expect targeted phishing posing as HR or interview contacts
  5. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources