SHINDO6

Sanrio Puroland

Personal dataup to2Mrecords

POSSIBLE LEAKMy Number / Date of birthRansomware · Investigating

Open in the live monitor ▶
Disclosed
Feb 7, 2025
Leak
Leak possible
Type
Ransomware
Status
Investigating
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name, Gender, Date of birth
ContactAddress, Phone number, Email address
Account dataSanrio+ ID (in some cases)
ID documentsContract information including My Number (specific personal information)
Transactions & activityContract information

How many

  • Personal data and other records (up to about 2 million) up to 2M records

Who is affected

  • Annual pass buyers for Sanrio Puroland and Harmonyland
  • Members of the former Puroland fan club
  • Sole proprietors and staff of business partners to whom payment records were issued

Cause

Ransomware attack. Network trouble occurred on January 21 and the investigation found the attack

Timeline

  1. Date the network trouble occurred
  2. Date of the Security NEXT report (earliest disclosure seen)

What you should do

  1. ID numbers can never be changed. Request your credit file from CIC, JICC and others and look for contracts or loans you didn't make
  2. Register a self-declaration (honnin shinkoku) with the credit bureaus so lenders check applications in your name more carefully. The stronger loan self-restriction scheme also blocks your own borrowing and can't be withdrawn for 3 months. Neither stops bank accounts being opened
  3. Don't open links in emails from this company. The apology email itself may be fake
  4. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  5. Watch for unexpected mail or invoices; your address is hard to change
  6. Check the company's notice to see if you're affected

Lessons for companies

  1. Offline backups with restore drills; segment the network
  2. Don't keep ID or bank data: delete after checks or use a KYC provider
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources