SHINDO4

Jobtora Academy

Personal data~350,000records

POSSIBLE LEAKPhone number / Full nameUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Feb 28, 2025
Detected
Feb 25, 2025
Detection to disclosure
3 days
Leak
Leak possible
Type
Unauthorized access
Status
Contained
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name, Gender, University, faculty and graduation year
ContactPhone number, Email address

How many

  • Members who registered between April 22, 2015 and May 18, 2023 ~350,000 records

Who is affected

  • Members who registered between April 22, 2015 and May 18, 2023

Cause

During database migration, traces of an apparent third-party intrusion were found on a work server

Timeline

  1. An employee found traces of compromise on a work server during database migration
  2. Date of the Security NEXT report

Response

  • Blocked the entry point
  • Service stopped

Stopped the compromised server and isolated related devices

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Check the company's notice to see if you're affected

Lessons for companies

  1. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  2. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources