SHINDO4

Japan Securities Dealers Association

Personal data13,320accounts

LEAK CONFIRMEDPassword / Login ID / usernameAccount takeover · Contained

Open in the live monitor ▶
Disclosed
Apr 3, 2025
Leak
Leak confirmed
Type
Account takeover
Status
Contained
Security spend
Not checked yet
Compensation
Compensation offered

What leaked

CredentialsLogin ID, Password

How many

  • Unauthorized access cases (FSA figures, sum of monthly counts January to June 2025) 13,320 accounts
  • Unauthorized trading cases (FSA figures, sum of monthly counts January to June 2025) 7,431 accounts

Who is affected

  • Customers of brokerages using online trading services

Cause

Unauthorized access and trading by third parties using customer data (login IDs, passwords, etc.) stolen through fake websites imitating real brokerages (phishing sites) and other means

Timeline

  1. Date the FSA first issued its warning
  2. Ten major and online brokerages agreed to compensate victims to a certain extent
  3. FSA updated its damage statistics

Response

  • MFA
  • Phishing warning

Ten firms agreed to compensate victims to a certain extent regardless of their terms. Customers were urged to turn on multi-factor authentication, use bookmarks for official sites and not open links in emails or SMS

What you should do

  1. Change this password and every account that reused it now. Switch to a passkey where offered
  2. Check the company's notice to see if you're affected

Lessons for companies

  1. Passkeys or MFA for every account; monitor leaked credentials and rotate API keys
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources