SHINDO4

NTT Communications

Personal data17,891organizations

POSSIBLE LEAKPostal address / Phone numberUnauthorized access · Investigating

Open in the live monitor ▶
Disclosed
Mar 6, 2025
Detected
Feb 5, 2025
Detection to disclosure
29 days
Leak
Leak possible
Type
Unauthorized access
Status
Investigating
Security spend
Not checked yet
Compensation
Not announced

What leaked

Business dataContract holder name, Contact person name
Transactions & activityContract number, Service usage information
ContactAddress, Phone number, Email address

How many

  • Corporate service customers 17,891 organizations

Who is affected

  • Corporate service customers

Cause

An internal device of the order information system, which manages service activation and change data, and another device in front of it on the internal network were compromised

Timeline

  1. Detected
  2. Date the compromise of another device was found
  3. Date of the Security NEXT report; the official announcement date was not checked

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Watch for unexpected mail or invoices; your address is hard to change
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  2. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources