SHINDO4

PR TIMES

Personal dataup to901,603records

POSSIBLE LEAKPhone number / Full nameUnauthorized access · Investigating

Open in the live monitor ▶
Disclosed
May 8, 2025
Detected
Apr 25, 2025
Detection to disclosure
13 days
Leak
Leak possible
Type
Unauthorized access
Status
Investigating
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name
Business dataCompany name
Employment & HRDepartment name
ContactPhone number, Email address
CredentialsHashed passwords (for users)

How many

  • Personal data records (total) up to 901,603 records
  • Corporate users 227,023 records
  • Press release recipients held by corporate users 331,619 records
  • Media users 28,274 records
  • Individual users 313,920 records

Who is affected

  • Corporate users
  • Press release recipients held by corporate users
  • Media users and individual users

Cause

From early April 2025 the company's servers were attacked and compromised. The attackers got past IP address restrictions and multi-factor authentication, and between April 24 and 25 wrote malicious files and installed backdoors

Timeline

  1. Intrusion began
  2. Detected
  3. Date of the Security NEXT report (announcement date)

What you should do

  1. Change this password and every account that reused it now. Weak passwords crack even when hashed or encrypted. Switch to a passkey where offered
  2. Don't open links in emails from this company. The apology email itself may be fake
  3. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  4. You can be affected without ever using this service (parcel recipients etc.). Check any notice you receive
  5. Check the company's notice to see if you're affected

Lessons for companies

  1. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  2. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources