SHINDO4
Japan Securities Dealers Association
Personal data13,320accounts
LEAK CONFIRMEDPassword / Login ID / usernameAccount takeover · Contained
Open in the live monitor ▶- Disclosed
- Apr 3, 2025
- Leak
- Leak confirmed
- Type
- Account takeover
- Status
- Contained
- Security spend
- Not checked yet
- Compensation
- Compensation offered
What leaked
CredentialsLogin ID, Password
How many
- Unauthorized access cases (FSA figures, sum of monthly counts January to June 2025) 13,320 accounts
- Unauthorized trading cases (FSA figures, sum of monthly counts January to June 2025) 7,431 accounts
Who is affected
- Customers of brokerages using online trading services
Cause
Unauthorized access and trading by third parties using customer data (login IDs, passwords, etc.) stolen through fake websites imitating real brokerages (phishing sites) and other means
Timeline
- Date the FSA first issued its warning
- Ten major and online brokerages agreed to compensate victims to a certain extent
- FSA updated its damage statistics
Response
- MFA
- Phishing warning
Ten firms agreed to compensate victims to a certain extent regardless of their terms. Customers were urged to turn on multi-factor authentication, use bookmarks for official sites and not open links in emails or SMS
What you should do
- Change this password and every account that reused it now. Switch to a passkey where offered
- Check the company's notice to see if you're affected
Lessons for companies
- Passkeys or MFA for every account; monitor leaked credentials and rotate API keys
- Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
- Run red teaming and AI-assisted hardening, and publish how much you invest
Sources
- Financial Services Agency (warning on surging unauthorized access and trading) Regulator · Apr 3, 2025
- Financial Services Agency (damage statistics) Regulator · Sep 9, 2026
- Japan Securities Dealers Association (10-firm agreement) Official notice · May 2, 2025
- Japan Securities Dealers Association Official notice