SHINDO3

RELIEF Ticket

MisconfigurationSize not disclosed

EXPOSEDBank account / Postal addressContained

Open in the live monitor ▶
Disclosed
Jun 26, 2025
Leak
Exposed, access unknown
Type
Misconfiguration
Status
Contained
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name, Date of birth
ContactAddress, Phone number, Email address
Financial & paymentLast three digits of credit card number, Cardholder name, Card expiry date, Bank name, branch, account holder name and account number

Who is affected

  • Some customers with login history

Cause

When the cache settings were revised on June 23, 2025, they were mistakenly set to store pages including cookies, so other customers visiting the site saw someone else's My Page as if logged in

Timeline

  1. Exposure began
  2. Exposure ended
  3. Date of the Security NEXT report

Response

  • Notified individuals
  • Config review

Emailed customers whose data was accessible or whose data was updated

What you should do

  1. Even the last 4 digits make a scam call sound genuine. Never give card details by phone or text
  2. Scammers who know your account number pose as refund staff. No bank or company asks for your PIN
  3. Don't open links in emails from this company. The apology email itself may be fake
  4. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  5. Watch for unexpected mail or invoices; your address is hard to change
  6. Check the company's notice to see if you're affected

Lessons for companies

  1. Two-person review and pre-release tests for sharing and cache changes; monitor cloud config (CSPM)
  2. Never sit on a known defect. Test every change before production
  3. Don't keep ID or bank data: delete after checks or use a KYC provider
  4. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  5. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources