SHINDO6

Rakumachi

Personal data~480,000accounts

POSSIBLE LEAKPassword / Credit / debt dataUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Jul 30, 2025
Detected
Jun 10, 2025 19:00 JST
Detection to disclosure
50 days
Leak
Leak possible
Type
Unauthorized access
Status
Contained
Security spend
Not checked yet
Compensation
Not announced

What leaked

ContactEmail address, Address, Phone number
CredentialsPassword
IdentityFull name
Financial & paymentAnnual income, Asset information
Business dataCompany name, representative and contact person, Property information

How many

  • Members (email address and password) ~480,000 accounts
  • Members with extended profile data ~310,000 accounts
  • Affiliated companies ~23,000 organizations

Who is affected

  • Members
  • Affiliated companies

Cause

A vulnerability in a web server was exploited to install a backdoor and extract database information

Timeline

  1. High database server load detected and suspicious commands stopped
  2. Date of the Security NEXT report

Response

  • Forensic investigation

What you should do

  1. Change this password and every account that reused it now. Switch to a passkey where offered
  2. Don't open links in emails from this company. The apology email itself may be fake
  3. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  4. Watch for unexpected mail or invoices; your address is hard to change
  5. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Don't keep ID or bank data: delete after checks or use a KYC provider
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources