SHINDO4
NTT Communications
NTT Communications Corporation
Personal data17,891organizations
POSSIBLE LEAKPostal address / Phone numberUnauthorized access · Investigating
Open in the live monitor ▶- Disclosed
- Mar 6, 2025
- Detected
- Feb 5, 2025
- Detection to disclosure
- 29 days
- Leak
- Leak possible
- Type
- Unauthorized access
- Status
- Investigating
- Security spend
- Not checked yet
- Compensation
- Not announced
What leaked
Business dataContract holder name, Contact person name
Transactions & activityContract number, Service usage information
ContactAddress, Phone number, Email address
How many
- Corporate service customers 17,891 organizations
Who is affected
- Corporate service customers
Cause
An internal device of the order information system, which manages service activation and change data, and another device in front of it on the internal network were compromised
Timeline
- Detected
- Date the compromise of another device was found
- Date of the Security NEXT report; the official announcement date was not checked
What you should do
- Don't open links in emails from this company. The apology email itself may be fake
- Treat refund or apology calls and texts as scams. Call back only on the number from the official site
- Watch for unexpected mail or invoices; your address is hard to change
- Check the company's notice to see if you're affected
Lessons for companies
- Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
- Run red teaming and AI-assisted hardening, and publish how much you invest
Sources
- Security NEXT News · Mar 6, 2025