SHINDO4

Recruit

Personal data481people

LEAK CONFIRMEDPhone number / Full nameInsider misuse · Closed (final report)

Open in the live monitor ▶
Disclosed
Aug 4, 2025
Detected
Apr 2025
Detection to disclosure
125 days
Leak
Leak confirmed
Type
Insider misuse
Status
Closed (final report)
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name
ContactPhone number, Email address
Business dataWorkplace
Employment & HRJob title, Department

How many

  • Staff of 255 lodging facilities 481 people
  • Recruit employees 55 people

Who is affected

  • Lodging facility staff
  • Employees

Cause

A former employee who left at the end of March 2024 took internal materials in breach of company rules and used them in outside business activities

Timeline

  1. Taken by a former employee who left at the end of March 2024
  2. Tip from an outside party
  3. Removal confirmed
  4. Date of the Security NEXT report

Response

  • Data deleted
  • Notified individuals
  • Governance / committee
  • Access review

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Expect targeted phishing posing as HR or interview contacts
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  2. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources