SHINDO3
RELIEF Ticket
PIA Corporation
MisconfigurationSize not disclosed
EXPOSEDBank account / Postal addressContained
Open in the live monitor ▶- Disclosed
- Jun 26, 2025
- Leak
- Exposed, access unknown
- Type
- Misconfiguration
- Status
- Contained
- Security spend
- Not checked yet
- Compensation
- Not announced
What leaked
IdentityFull name, Date of birth
ContactAddress, Phone number, Email address
Financial & paymentLast three digits of credit card number, Cardholder name, Card expiry date, Bank name, branch, account holder name and account number
Who is affected
- Some customers with login history
Cause
When the cache settings were revised on June 23, 2025, they were mistakenly set to store pages including cookies, so other customers visiting the site saw someone else's My Page as if logged in
Timeline
- Exposure began
- Exposure ended
- Date of the Security NEXT report
Response
- Notified individuals
- Config review
Emailed customers whose data was accessible or whose data was updated
What you should do
- Even the last 4 digits make a scam call sound genuine. Never give card details by phone or text
- Scammers who know your account number pose as refund staff. No bank or company asks for your PIN
- Don't open links in emails from this company. The apology email itself may be fake
- Treat refund or apology calls and texts as scams. Call back only on the number from the official site
- Watch for unexpected mail or invoices; your address is hard to change
- Check the company's notice to see if you're affected
Lessons for companies
- Two-person review and pre-release tests for sharing and cache changes; monitor cloud config (CSPM)
- Never sit on a known defect. Test every change before production
- Don't keep ID or bank data: delete after checks or use a KYC provider
- Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
- Run red teaming and AI-assisted hardening, and publish how much you invest
Sources
- Security NEXT News · Jun 26, 2025